Python Requests使用自签名证书遭遇SSL验证失败问题求助
问题:Python请求自签名证书服务时SSL验证失败(适配Azure Functions)
我已查阅相关旧讨论帖,但其中的解决方案均无效。测试机上已将私有CA的ca.pem添加至/usr/local/share/ca-certificates/ca.crt,执行curl https://example.com:8000/health可正常获取输出,但用Python实现相同请求时持续报错。当前使用Python 3.10.12,certifi证书路径为/home/normal/.local/lib/python3.10/site-packages/certifi/cacert.pem。
报错信息
requests.exceptions.SSLError: HTTPSConnectionPool(host='example.com', port=8000): Max retries exceeded with url: /health (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1007)')))
已尝试的解决方案
- 设置
REQUESTS_CA_BUNDLE环境变量:
ca_path = os.path.join( '/usr/local/share/ca-certificates/', 'ca.crt') print(ca_path) os.environ['REQUESTS_CA_BUNDLE'] = ca_path
- 为
requests.post的verify参数指定私有CA路径:
response = requests.post(url, verify=ca_path)
- 为
verify参数指定certifi默认证书路径:
response = requests.post(url, verify=certifi.where())
- 创建包含证书链的
fullchain.pem并指定验证路径:
cat cert.pem > fullchain.pem cat ca.pem >> fullchain.pem
response = requests.post(url, verify='./fullchain.pem')
- 向certifi的
cacert.pem追加私有证书:
cd /home/<usr>/.local/lib/python3.10/site-packages/certifi cp cacert.pem cacert.pem.bak cat cacert.pem.bak <(echo) ca.pem <(echo) cert.pem > cacert.pem
需求
希望找到可适配Azure Functions运行环境的有效解决方案。
内容的提问来源于stack exchange,提问作者Saksham
相关产品推荐
相关产品推荐

