Windows环境调用Google Vertex AI预测遇SSL证书验证失败求助
我正尝试使用Google Vertex AI预测模型,通过以下代码进行数据点预测:
from google.cloud import aiplatform import os project_id = "project_id" location = "us-central1" endpoint_id = "399999999999999999" ai_ep_client_options = {"api_endpoint": "us-central1-aiplatform.googleapis.com"} os.environ['GOOGLE_APPLICATION_CREDENTIALS'] = "service-key.json" instance_list = [{"feature-1":"apple", "feature-2": "banana"}] aiplatform_client = aiplatform.gapic.PredictionServiceClient(client_options=ai_ep_client_options) prediction_endpoint_client = aiplatform_client.endpoint_path(project=project_id, location=location, endpoint=endpoint_id) response = aiplatform_client.predict(endpoint=prediction_endpoint_client, instances=instance_list)
运行后出现SSL证书验证失败的错误:
_InactiveRpcError Traceback (most recent call last) File
~\AppData\Local\anaconda3\Lib\site-packages\google\api_core\grpc_helpers.py:50,
in wrap_unary_errors..error_remapped_callable(*args,
**kwargs)
49 try:
---> 50 return callable(*args, **kwargs)
51 except grpc.RpcError as exc:File
~\AppData\Local\anaconda3\Lib\site-packages\grpc_channel.py:1161, in
_UnaryUnaryMultiCallable.call(self, request, timeout, metadata, credentials, wait_for_ready, compression) 1155 ( 1156 state,
1157 call, 1158 ) = self._blocking( 1159 request,
timeout, metadata, credentials, wait_for_ready, compression 1160 )
---> 1161 return _end_unary_response_blocking(state, call, False, None)File
~\AppData\Local\anaconda3\Lib\site-packages\grpc_channel.py:1004, in
_end_unary_response_blocking(state, call, with_call, deadline) 1003 else:
---> 1004 raise _InactiveRpcError(state)_InactiveRpcError: <_InactiveRpcError of RPC that terminated with: status = StatusCode.UNAVAILABLE details = "failed to connect to all
addresses; last error: UNKNOWN: ipv4:142.250.31.95:443: Ssl handshake
failed: SSL_ERROR_SSL: error:1000007d:SSL
routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED"
debug_error_string = "UNKNOWN:failed to connect to all addresses;
last error: UNKNOWN: ipv4:xxx.xxx.xxx.x:443: Ssl handshake failed:
SSL_ERROR_SSL: error:1000007d:SSL
routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED
{created_time:"2023-11-03T11:03:27.2979758+00:00", grpc_status:14}"上述异常直接引发了以下异常:
ServiceUnavailable Traceback (most recent call
last) Cell In[18], line 16
13 aiplatform_client = aiplatform.gapic.PredictionServiceClient(client_options=ai_ep_client_options)
14 prediction_endpoint_client = aiplatform_client.endpoint_path(project=project_id, location=location,
endpoint=endpoint_id)
---> 16 response = aiplatform_client.predict(endpoint=prediction_endpoint_client,
instances=instance_list)
17 responseFile
~\AppData\Local\anaconda3\Lib\site-packages\google\cloud\aiplatform_v1\services\prediction_service\client.py:602,
in PredictionServiceClient.predict(self, request, endpoint, instances,
parameters, retry, timeout, metadata)
597 metadata = tuple(metadata) + (
598 gapic_v1.routing_header.to_grpc_metadata((("endpoint", request.endpoint),)),
599 )
601 # Send the request.
---> 602 response = rpc(
603 request,
604 retry=retry,
605 timeout=timeout,
606 metadata=metadata,
607 )
609 # Done; return the response.
610 return responseFile
~\AppData\Local\anaconda3\Lib\site-packages\google\api_core\gapic_v1\method.py:154,
in _GapicCallable.call(self, timeout, retry, *args, **kwargs)
151 metadata.extend(self._metadata)
152 kwargs["metadata"] = metadata
---> 154 return wrapped_func(*args, **kwargs)File
~\AppData\Local\anaconda3\Lib\site-packages\google\api_core\grpc_helpers.py:52,
in wrap_unary_errors..error_remapped_callable(*args,
**kwargs)
50 return callable(*args, **kwargs)
51 except grpc.RpcError as exc:
---> 52 raise exceptions.from_grpc_error(exc) from excServiceUnavailable: 503 failed to connect to all addresses; last
error: UNKNOWN: ipv4:xxx.xx.xx.xx:443: Ssl handshake failed:
SSL_ERROR_SSL: error:1000007d:SSL
routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED
环境信息:Windows系统,aiplatform.__version__为1.28.1,企业机器,此前代码正常运行,系统安全更新后出现该问题。
1. 配置系统根证书到Python环境
企业安全更新可能替换了系统根证书,需让Python的OpenSSL识别新证书:
- 导出系统根证书:
- 按下Win+R,输入
certmgr.msc打开证书管理器 - 展开「受信任的根证书颁发机构」→「证书」
- 右键选择对应Google服务的证书(或所有根证书),点击「所有任务」→「导出」
- 选择「Base-64编码的X.509(.CER)」格式,保存为
root_certs.cer文件
- 按下Win+R,输入
- 在代码中指定证书路径:
也可直接在系统环境变量中添加import os os.environ['SSL_CERT_FILE'] = "C:/path/to/your/root_certs.cer"SSL_CERT_FILE,值为证书文件的绝对路径。
2. 更新依赖库
旧版本的gRPC和Google客户端库可能不兼容新证书,执行以下命令更新:
pip install --upgrade grpcio google-cloud-aiplatform google-api-core
3. 配置企业代理(若存在)
企业机器通常有代理,需确保Python能通过代理访问Vertex AI:
- 代码中添加代理配置:
import grpc from google.cloud import aiplatform # 替换为企业代理的IP和端口 proxy_channel = grpc.insecure_channel("http://proxy-ip:proxy-port") channel = grpc.intercept_channel(proxy_channel, grpc.proxy_credentials()) aiplatform_client = aiplatform.gapic.PredictionServiceClient( client_options=ai_ep_client_options, channel=channel ) - 或设置系统环境变量
HTTP_PROXY和HTTPS_PROXY,值为企业代理地址(格式示例:http://proxy-user:proxy-pass@proxy-ip:proxy-port)。
4. 验证证书有效性
若已安装OpenSSL工具,执行以下命令验证连接:
openssl s_client -connect us-central1-aiplatform.googleapis.com:443
若返回证书验证成功,说明网络和证书无问题;若失败,联系企业IT部门确认证书部署情况。
内容的提问来源于stack exchange,提问作者Rajiv2806

