You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

公司代理环境下pip安装tensorstore遇SSL证书验证失败求助

公司自签名代理环境下pip安装tensorstore的SSL证书验证失败问题

执行pip安装tensorstore时,因bazelisk.py脚本通过urllib下载Bazel资源时触发SSL证书验证失败错误:

$ pip install --trusted-host=example.com --index-url=http://example.com/pypi/simple
...
  Downloading https://releases.bazel.build/6.4.0/release/bazel-6.4.0-linux-arm64...
  Traceback (most recent call last):
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 1346, in do_open
      h.request(req.get_method(), req.selector, req.data, headers,
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1285, in request
      self._send_request(method, url, body, headers, encode_chunked)
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1331, in _send_request
      self.endheaders(body, encode_chunked=encode_chunked)
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1280, in endheaders
      self._send_output(message_body, encode_chunked=encode_chunked)
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1040, in _send_output
      self.send(msg)
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 980, in send
      self.connect()
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1454, in connect
      self.sock = self._context.wrap_socket(self.sock,
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/ssl.py", line 500, in wrap_socket
      return self.sslsocket_class._create(
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/ssl.py", line 1040, in _create
      self.do_handshake()
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/ssl.py", line 1309, in do_handshake
      self._sslobj.do_handshake()
  ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1129)

  During handling of the above exception, another exception occurred:

  Traceback (most recent call last):
    File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 492, in <module>
      sys.exit(main())
    File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 477, in main
      bazel_path = get_bazel_path()
    File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 470, in get_bazel_path
      return download_bazel_into_directory(bazel_version, is_commit, bazel_directory)
    File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 304, in download_bazel_into_directory
      download(bazel_url, destination_path)
    File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 353, in download
      with closing(urlopen(request)) as response, open(destination_path, "wb") as file:
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 214, in urlopen
      return opener.open(url, data, timeout)
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 517, in open
      response = self._open(req, data)
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 534, in _open
      result = self._call_chain(self.handle_open, protocol, protocol +
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 494, in _call_chain
      result = func(*args)
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 1389, in https_open
      return self.do_open(http.client.HTTPSConnection, req,
    File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 1349, in do_open
      raise URLError(err)
  urllib.error.URLError: <urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1129)>
  error: command '/home/user/anaconda3/envs/PyTorch-1.11.0/bin/python3.9' failed with exit code 1
  ----------------------------------------
  ERROR: Failed building wheel for tensorstore
Failed to build tensorstore
ERROR: Could not build wheels for tensorstore which use PEP 517 and cannot be installed directly

已尝试的无效操作

  • 配置系统证书:将公司证书放入/etc/pki/ca-trust/source/anchors并执行update-ca-trust,curl访问HTTPS站点正常,但pip安装仍失败
  • 替换certifi证书:安装certifi后将其PEM文件替换为指向系统证书的软链接,重试无效
  • 设置REQUESTS_CA_BUNDLE:因bazelisk.py使用urllib而非requests,该变量不生效
  • 无法修改临时下载的bazelisk.py脚本添加SSL跳过验证逻辑

可行解决方案

方法1:通过环境变量指定Python SSL证书路径

直接设置SSL_CERT_FILE环境变量指向系统更新后的证书,让urllib底层的ssl模块使用该证书:

SSL_CERT_FILE="/etc/pki/tls/cert.pem" pip install --trusted-host=example.com --index-url=http://example.com/pypi/simple tensorstore

方法2:预先下载Bazel跳过bazelisk自动下载

  1. 用curl手动下载对应版本的Bazel(版本号需匹配错误提示中的版本):
    curl -O https://releases.bazel.build/6.4.0/release/bazel-6.4.0-linux-arm64
    
  2. 赋予执行权限并移动到系统可执行路径:
    chmod +x bazel-6.4.0-linux-arm64
    sudo mv bazel-6.4.0-linux-arm64 /usr/local/bin/bazel
    
  3. 重新执行pip安装,此时bazelisk会检测到本地已存在Bazel,跳过下载步骤:
    pip install --trusted-host=example.com --index-url=http://example.com/pypi/simple tensorstore
    

方法3:临时修改Python SSL默认上下文

创建临时脚本fix_ssl.py:

import ssl

# 强制SSL上下文使用系统证书
ssl._create_default_https_context = lambda: ssl.create_default_context(cafile='/etc/pki/tls/cert.pem')

加载该脚本后执行pip安装:

PYTHONPATH=. python -c "import fix_ssl; from pip._internal import main; main(['install', '--trusted-host=example.com', '--index-url=http://example.com/pypi/simple', 'tensorstore'])"

内容的提问来源于stack exchange,提问作者Green 绿色

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 02:47:02