You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何不同版本certifi的cacert.pem有效期相同?2028年后会自动更新吗?

关于certifi模块cacert.pem有效期的疑问与解答

疑问1:为何不同版本的certifi,其cacert.pem的有效期完全相同?

你观察到certifi 2018.4.16和2024.2.2版本的cacert.pem显示的有效期一致,核心原因是:

  • certifi的cacert.pem是Mozilla根证书bundle的副本,这个文件包含多个根证书的集合。
  • 你使用的openssl x509 -enddate命令默认只会读取并显示文件中第一个证书的有效期。两个版本的bundle里,排在首位的恰好是同一张有效期到2028年1月28日的根证书,所以输出结果一致。
  • 不同版本的certifi更新的是bundle内的证书列表(比如新增可信根证书、移除过期/不合规的证书),并非替换所有证书,因此首位证书未变时,单条命令的输出就会相同。

可以通过以下命令验证bundle内所有证书的有效期差异:

# 将cacert.pem拆分单个证书文件
awk 'BEGIN {c=0;} /BEGIN CERTIFICATE/ {c++} {print > "cert" c ".pem"}' < /usr/local/lib/python3.3/site-packages/certifi/cacert.pem
# 遍历所有拆分后的证书,查看各自有效期
for cert in cert*.pem; do echo "--- $cert ---"; openssl x509 -enddate -noout -in $cert; done

你提供的两个版本验证结果:

certifi 2018.4.16版本信息及验证结果

[root@8a63ff0c0dba /]# python3.3 -m pip show certifi
Name: certifi
Version: 2018.4.16
Summary: Python package for providing Mozillas CA Bundle.
Home-page: http://certifi.io/
Author: Kenneth Reitz
Author-email: me@kennethreitz.com
License: MPL-2.0
Location: /usr/local/lib/python3.3/site-packages
Requires: 
Required-by: requests

[root@8a63ff0c0dba /]# openssl x509 -enddate -noout -in /usr/local/lib/python3.3/site-packages/certifi/cacert.pem
notAfter=Jan 28 12:00:00 2028 GMT

certifi 2024.2.2版本信息及验证结果

[root@1e6dfr05dhd /]# python3.11 -m pip show certifi
Name: certifi
Version: 2024.2.2
Summary: Python package for providing Mozillas CA Bundle.
Home-page: https://github.com/certifi/python-certifi
Author: Kenneth Reitz
Author-email: me@kennethreitz.com
License: MPL-2.0
Location: /usr/local/lib/python3.11/site-packages
Requires: 
Required-by: requests

[root@1e6dfr05dhd /]# openssl x509 -enddate -noout -in /usr/local/lib/python3.11/site-packages/certifi/cacert.pem
notAfter=Jan 28 12:00:00 2028 GMT

疑问2:2028年1月28日之后,cacert.pem的有效期会自动更新吗?

不会自动更新。certifi是静态的Python包,安装到本地后,cacert.pem文件就固定下来了。要获取更新后的根证书bundle,你需要手动执行升级命令更新certifi到最新版本:

pip install --upgrade certifi

新版本的certifi会同步Mozilla最新的根证书集合,替换掉过期证书,确保你的证书bundle始终包含有效的可信根证书。


内容的提问来源于stack exchange,提问作者Kavin Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 00:47:21