You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

pip安装/升级库遇SSL自签名证书链验证失败问题求助

永久解决pip SSL证书验证失败问题

问题详情

执行pip install --upgrade pip时出现SSL证书链自签名错误,多次重试后无法获取PyPI资源,临时使用--trusted-host参数可绕过验证,但需要永久解决。错误信息如下:

C:\Users\1234567>pip install --upgrade pip
Requirement already satisfied: pip in c:\users\800710350\appdata\local\programs\python\python311\lib\site-packages (23.2.1)
WARNING: Retrying (Retry(total=4, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)'))': /simple/pip/
WARNING: Retrying (Retry(total=3, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)'))': /simple/pip/
WARNING: Retrying (Retry(total=2, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)'))': /simple/pip/
WARNING: Retrying (Retry(total=1, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)'))': /simple/pip/
WARNING: Retrying (Retry(total=0, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)'))': /simple/pip/
Could not fetch URL https://pypi.org/simple/pip/: There was a problem confirming the ssl certificate: HTTPSConnectionPool(host='pypi.org', port=443): Max retries exceeded with url: /simple/pip/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate in certificate chain (_ssl.c:1006)'))) - skipping

已尝试以下操作但未解决:

  • 使用pip install --trusted-host pypi.org --trusted-host files.pythonhosted.org临时绕过
  • 禁用防火墙与代理
  • 尝试升级pip
  • 通过Windows证书管理器安装证书

永久解决办法

1. 创建/修改pip全局配置文件

Windows系统中,pip配置文件有两个生效位置:

  • 用户级:%APPDATA%\pip\pip.ini(仅当前用户生效)
  • 全局级:C:\ProgramData\pip\pip.ini(所有用户生效)

若文件不存在,直接新建。打开文件后添加以下内容:

[global]
trusted-host = pypi.org
               files.pythonhosted.org
               pypi.python.org

保存后,后续执行pip命令会自动应用信任主机设置,无需每次手动加参数。

2. 指定自定义CA证书路径

如果是企业内网的自签名证书,将证书文件(.crt格式)放到固定路径(如C:\certs\internal.crt),然后在pip.ini中添加:

[global]
cert = C:\certs\internal.crt

这样pip会使用指定证书完成SSL连接验证。

3. 设置系统环境变量

通过环境变量让Python的SSL模块识别自定义证书:

  1. 右键「此电脑」→属性→高级系统设置→环境变量
  2. 点击「系统变量」下的「新建」,变量名填REQUESTS_CA_BUNDLE,变量值填证书文件的绝对路径(如C:\certs\internal.crt)
  3. 重启终端或IDE后生效,所有依赖requests库的工具(包括pip)都会使用该证书验证SSL。

4. 切换国内PyPI镜像(备选)

如果以上方法无效,可改用国内稳定镜像源,同时配置信任主机:
编辑pip.ini添加:

[global]
index-url = https://pypi.tuna.tsinghua.edu.cn/simple
trusted-host = pypi.tuna.tsinghua.edu.cn

国内镜像通常证书配置正常,可规避SSL验证问题。

内容的提问来源于stack exchange,提问作者Drashti

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 00:23:12