公司代理环境下pip安装tensorstore遇SSL证书验证失败求助
公司自签名代理环境下pip安装tensorstore的SSL证书验证失败问题
执行pip安装tensorstore时,因bazelisk.py脚本通过urllib下载Bazel资源时触发SSL证书验证失败错误:
$ pip install --trusted-host=example.com --index-url=http://example.com/pypi/simple ... Downloading https://releases.bazel.build/6.4.0/release/bazel-6.4.0-linux-arm64... Traceback (most recent call last): File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 1346, in do_open h.request(req.get_method(), req.selector, req.data, headers, File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1285, in request self._send_request(method, url, body, headers, encode_chunked) File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1331, in _send_request self.endheaders(body, encode_chunked=encode_chunked) File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1280, in endheaders self._send_output(message_body, encode_chunked=encode_chunked) File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1040, in _send_output self.send(msg) File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 980, in send self.connect() File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/http/client.py", line 1454, in connect self.sock = self._context.wrap_socket(self.sock, File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/ssl.py", line 500, in wrap_socket return self.sslsocket_class._create( File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/ssl.py", line 1040, in _create self.do_handshake() File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/ssl.py", line 1309, in do_handshake self._sslobj.do_handshake() ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1129) During handling of the above exception, another exception occurred: Traceback (most recent call last): File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 492, in <module> sys.exit(main()) File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 477, in main bazel_path = get_bazel_path() File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 470, in get_bazel_path return download_bazel_into_directory(bazel_version, is_commit, bazel_directory) File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 304, in download_bazel_into_directory download(bazel_url, destination_path) File "/tmp/pip-install-ycop_psv/tensorstore_1008eee73d464825b2e191c044b9e306/bazelisk.py", line 353, in download with closing(urlopen(request)) as response, open(destination_path, "wb") as file: File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 214, in urlopen return opener.open(url, data, timeout) File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 517, in open response = self._open(req, data) File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 534, in _open result = self._call_chain(self.handle_open, protocol, protocol + File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 494, in _call_chain result = func(*args) File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 1389, in https_open return self.do_open(http.client.HTTPSConnection, req, File "/home/user/anaconda3/envs/PyTorch-1.11.0/lib/python3.9/urllib/request.py", line 1349, in do_open raise URLError(err) urllib.error.URLError: <urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1129)> error: command '/home/user/anaconda3/envs/PyTorch-1.11.0/bin/python3.9' failed with exit code 1 ---------------------------------------- ERROR: Failed building wheel for tensorstore Failed to build tensorstore ERROR: Could not build wheels for tensorstore which use PEP 517 and cannot be installed directly
已尝试的无效操作
- 配置系统证书:将公司证书放入
/etc/pki/ca-trust/source/anchors并执行update-ca-trust,curl访问HTTPS站点正常,但pip安装仍失败 - 替换certifi证书:安装
certifi后将其PEM文件替换为指向系统证书的软链接,重试无效 - 设置
REQUESTS_CA_BUNDLE:因bazelisk.py使用urllib而非requests,该变量不生效 - 无法修改临时下载的
bazelisk.py脚本添加SSL跳过验证逻辑
可行解决方案
方法1:通过环境变量指定Python SSL证书路径
直接设置SSL_CERT_FILE环境变量指向系统更新后的证书,让urllib底层的ssl模块使用该证书:
SSL_CERT_FILE="/etc/pki/tls/cert.pem" pip install --trusted-host=example.com --index-url=http://example.com/pypi/simple tensorstore
方法2:预先下载Bazel跳过bazelisk自动下载
- 用
curl手动下载对应版本的Bazel(版本号需匹配错误提示中的版本):curl -O https://releases.bazel.build/6.4.0/release/bazel-6.4.0-linux-arm64 - 赋予执行权限并移动到系统可执行路径:
chmod +x bazel-6.4.0-linux-arm64 sudo mv bazel-6.4.0-linux-arm64 /usr/local/bin/bazel - 重新执行pip安装,此时bazelisk会检测到本地已存在Bazel,跳过下载步骤:
pip install --trusted-host=example.com --index-url=http://example.com/pypi/simple tensorstore
方法3:临时修改Python SSL默认上下文
创建临时脚本fix_ssl.py:
import ssl # 强制SSL上下文使用系统证书 ssl._create_default_https_context = lambda: ssl.create_default_context(cafile='/etc/pki/tls/cert.pem')
加载该脚本后执行pip安装:
PYTHONPATH=. python -c "import fix_ssl; from pip._internal import main; main(['install', '--trusted-host=example.com', '--index-url=http://example.com/pypi/simple', 'tensorstore'])"
内容的提问来源于stack exchange,提问作者Green 绿色
相关产品推荐
相关产品推荐

