You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python Requests使用自签名证书遭遇SSL验证失败问题求助

问题:Python请求自签名证书服务时SSL验证失败(适配Azure Functions)

我已查阅相关旧讨论帖,但其中的解决方案均无效。测试机上已将私有CA的ca.pem添加至/usr/local/share/ca-certificates/ca.crt,执行curl https://example.com:8000/health可正常获取输出,但用Python实现相同请求时持续报错。当前使用Python 3.10.12,certifi证书路径为/home/normal/.local/lib/python3.10/site-packages/certifi/cacert.pem。

报错信息

requests.exceptions.SSLError: HTTPSConnectionPool(host='example.com', port=8000): Max retries exceeded with url: /health (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1007)')))

已尝试的解决方案

  • 设置REQUESTS_CA_BUNDLE环境变量:
ca_path = os.path.join(
    '/usr/local/share/ca-certificates/',
    'ca.crt')
print(ca_path)
os.environ['REQUESTS_CA_BUNDLE'] = ca_path
  • 为requests.post的verify参数指定私有CA路径:
response = requests.post(url, verify=ca_path)
  • 为verify参数指定certifi默认证书路径:
response = requests.post(url, verify=certifi.where())
  • 创建包含证书链的fullchain.pem并指定验证路径:
cat cert.pem > fullchain.pem
cat ca.pem >> fullchain.pem
response = requests.post(url, verify='./fullchain.pem')
  • 向certifi的cacert.pem追加私有证书:
cd /home/<usr>/.local/lib/python3.10/site-packages/certifi

cp cacert.pem cacert.pem.bak
cat cacert.pem.bak <(echo) ca.pem <(echo) cert.pem > cacert.pem

需求

希望找到可适配Azure Functions运行环境的有效解决方案。

内容的提问来源于stack exchange,提问作者Saksham

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 17:03:17