You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS7.9镜像编译Python3.9.17+OpenSSL1.1.1t后SSL证书验证失败求助

解决自定义编译Python关联OpenSSL后的SSL证书验证失败问题

问题场景

从源码编译Python-3.9.17并关联自定义编译的OpenSSL-1.1.1t,已通过--with-openssl=/path/to/ssl参数完成配置,SSL模块安装成功,但使用urllib.request.Request访问部分网站时,抛出以下错误:

urllib.error.URLError: <urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)

问题原因

自定义编译的OpenSSL默认不会自动加载系统根证书,而Python的ssl模块依赖OpenSSL的证书信任链来验证网站证书。CentOS 7的系统根证书存放在/etc/pki/tls/certs/ca-bundle.crt,但自定义安装的OpenSSL未指向该路径,导致无法找到可信任的根证书。

解决方案

方法1:让自定义OpenSSL使用系统根证书

将系统根证书复制到OpenSSL的配置目录,并修改OpenSSL配置文件指向该证书:

# 在OpenSSL安装完成后添加以下步骤
RUN cp /etc/pki/tls/certs/ca-bundle.crt /usr/local/ssl/certs/ca-certificates.crt
RUN echo "CERTIFICATE_PATH=/usr/local/ssl/certs/ca-certificates.crt" >> /usr/local/ssl/openssl.cnf

方法2:给Python指定证书路径

通过设置环境变量SSL_CERT_FILE让Python直接使用系统根证书:

# 在Python安装完成后添加
ENV SSL_CERT_FILE=/etc/pki/tls/certs/ca-bundle.crt

方法3:安装certifi包(推荐)

certifi是Python的证书管理包,包含Mozilla维护的根证书集合,安装后Python会自动使用其证书:

# 在安装pip后添加
RUN pip3 install certifi

修改后的完整Dockerfile

FROM centos:centos7.9.2009

MAINTAINER kavin<mkavink2000@gmail.com>

WORKDIR /root/install
SHELL ["/bin/bash", "-c"]

RUN yes "yes" | yum update --nogpgcheck
RUN yes "yes" | yum install wget --nogpgcheck
RUN yes "yes" | yum update --nogpgcheck
RUN yes "yes" | yum install libffi-devel --nogpgcheck
RUN yes "yes" | yum install make --nogpgcheck
RUN yes "yes" | yum install gcc --nogpgcheck
RUN yes "yes" | yum install zlib-devel --nogpgcheck


RUN wget https://ftp.openssl.org/source/old/1.1.1/openssl-1.1.1t.tar.gz
RUN wget https://www.python.org/ftp/python/3.9.17/Python-3.9.17.tgz
RUN wget https://www.cpan.org/src/5.0/perl-5.38.0.tar.gz
RUN wget https://bootstrap.pypa.io/pip/get-pip.py


RUN tar -zxf perl-5.38.0.tar.gz
WORKDIR perl-5.38.0
RUN sh Configure -de
RUN make && make install


WORKDIR /root/install/
RUN tar -zxf openssl-1.1.1t.tar.gz
WORKDIR openssl-1.1.1t
RUN ./config --prefix=/usr/local/ssl --openssldir=/usr/local/ssl shared zlib
RUN make clean
RUN make && make install
RUN printf "/usr/local/ssl/lib" > /etc/ld.so.conf.d/openssl.conf
RUN ldconfig
ENV PATH="$PATH:/usr/local/ssl/bin"
RUN printf PATH="$PATH" > /etc/environment
RUN source /etc/environment

# 添加:让OpenSSL使用系统根证书
RUN cp /etc/pki/tls/certs/ca-bundle.crt /usr/local/ssl/certs/ca-certificates.crt
RUN echo "CERTIFICATE_PATH=/usr/local/ssl/certs/ca-certificates.crt" >> /usr/local/ssl/openssl.cnf


WORKDIR /root/install
RUN tar -zxf Python-3.9.17.tgz
WORKDIR Python-3.9.17

# Configure Setup for Custom OpenSSl
RUN sed -i "/SSL=\/usr\/local\/ssl/c\SSL=/usr/local/ssl" Modules/Setup
RUN sed -i "/_ssl _ssl.c/c\_ssl _ssl.c \\" Modules/Setup
RUN sed -i '/-DUSE_SSL/c\   -DUSE_SSL -I\$(SSL)/include -I\$(SSL)/include/openssl \\' Modules/Setup
RUN sed -i '/-L$(SSL)\/lib/c\   -L\$(SSL)\/lib -lssl -lcrypto' Modules/Setup
RUN sed -i '/_socket socketmodule.c/c\_socket socketmodule.c' Modules/Setup
RUN sed -i '/_md5 md5module.c/c\_md5 md5module.c' Modules/Setup
RUN sed -i '/_sha1 sha1module.c/c\_sha1 sha1module.c' Modules/Setup
RUN sed -i '/_sha256 sha256module.c/c\_sha256 sha256module.c -DPy_BUILD_CORE_BUILTIN' Modules/Setup
RUN sed -i '/_sha512 sha512module.c/c\_sha512 sha512module.c -DPy_BUILD_CORE_BUILTIN' Modules/Setup
RUN sed -i '/_sha3 _sha3\/sha3module.c/c\_sha3 _sha3\/sha3module.c' Modules/Setup
RUN sed -i '/zlib zlibmodule/c\zlib zlibmodule.c -I\$(prefix)\/include -L\$(exec_prefix)\/lib -lz' Modules/Setup

WORKDIR /root/install
WORKDIR Python-3.9.17

ENV LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/usr/local/ssl/lib"
RUN ./configure --with-openssl=/usr/local/ssl
RUN make clean
RUN make && make install
RUN ldconfig


WORKDIR /root/install/
RUN python3.9 get-pip.py

# 可选:安装certifi包增强证书支持
RUN pip3 install certifi


WORKDIR /
RUN printf "import urllib.request\n" > test_ssl.py
RUN printf "req = urllib.request.Request('https://stackoverflow.com/')\n" >> test_ssl.py
RUN printf "resp = urllib.request.urlopen(req)\n" >> test_ssl.py
RUN printf "print(resp.headers)\n" >> test_ssl.py
RUN printf "print(resp.read())\n" >> test_ssl.py

RUN python3 test_ssl.py

内容的提问来源于stack exchange,提问作者Kavin Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 14:52:03