You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无合理原因的SSL验证阻止ConnectWise API查询求助

问题描述

编写Python脚本从ConnectWise提取公司信息时,调用官方API遇到SSL证书验证错误,错误信息如下:

Traceback (most recent call last):
  File "C:\...\urllib3\connectionpool.py", line 467, in _make_request
    self._validate_conn(conn)
  ...
    ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "C:\...\urllib3\connectionpool.py", line 790, in urlopen
    response = self._make_request(
  ...
urllib3.exceptions.MaxRetryError: HTTPSConnectionPool(host='example.com', port=443): Max retries exceeded with url: /path (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)')))

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "path\to\your\script.py", line 26, in <module>
    main()
  ...
requests.exceptions.SSLError: HTTPSConnectionPool(host='example.com', port=443): Max retries exceeded with url: /path (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)')))

已知禁用SSL验证不符合安全规范,当前使用Python 3.11.7虚拟环境,已升级certifi但无效果。老板电脑和Postman可正常执行查询,怀疑问题出在虚拟环境,求合规解决方案。

解决方案

1. 导出信任的根证书

从能正常访问的环境(老板电脑浏览器或Postman)导出ConnectWise服务器的根证书(PEM格式):

  • Postman操作:访问API后,点击地址栏左侧的锁图标 → 「查看证书」 → 切换到「证书链」标签 → 选中最顶层的根证书 → 点击「导出」,保存为PEM格式文件。
  • 浏览器操作:访问ConnectWise API域名,点击地址栏锁图标 → 「证书」 → 「详细信息」 → 「复制到文件」,选择Base64编码的X.509(.CER)格式,保存后将文件后缀改为.pem。

2. 让虚拟环境的请求信任该证书

有两种合规方式:

方式一:单请求指定证书

在调用API时直接传入证书路径:

import requests

# 替换为你的API地址和证书路径
response = requests.get("https://your-connectwise-api-endpoint", verify="/path/to/exported-cert.pem")

方式二:将证书添加到虚拟环境的certifi证书池

如果需要所有请求都信任该证书,可把证书追加到虚拟环境的CA证书库中:

  1. 找到虚拟环境中certifi的证书文件路径:
    import certifi
    print(certifi.where())
    # 输出类似:C:\your-venv\Lib\site-packages\certifi\cacert.pem
    
  2. 用文本编辑器打开该cacert.pem文件,将导出的PEM格式证书内容粘贴到文件末尾,保存即可。

3. 检查虚拟环境的SSL环境变量

确认虚拟环境没有设置错误的REQUESTS_CA_BUNDLE环境变量:

  • 若之前手动设置过该变量,确保其指向正确的证书文件或certifi的cacert.pem路径;
  • 若不需要自定义,可删除该环境变量,让requests默认使用certifi的证书池。

内容的提问来源于stack exchange,提问作者drtaylor1701

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 23:47:45