如何在CentOS 7中将Python3及pyOpenSSL链接至OpenSSL 1.1.1(openssl11)
Absolutely, you can link Python and pyOpenSSL with the openssl11 package on CentOS 7—even though this package is labeled for temporary use, you can get it working reliably for your needs. Here's a step-by-step guide to make it happen:
Prerequisites
First, make sure you have openssl11 and its development files installed (the devel package is critical for compiling pyOpenSSL against the newer library):
# Check if openssl11 is already installed yum list installed openssl11 # If not, install both the runtime and development packages yum install -y openssl11 openssl11-devel
Step 1: Configure Environment Variables
We need to tell your system (and Python's package installer) where to find the newer OpenSSL 1.1.1 headers and libraries. Run these commands to set temporary environment variables:
# Point to openssl11's libraries export LD_LIBRARY_PATH=/usr/lib64/openssl11/:$LD_LIBRARY_PATH # Tell compilers where to find the headers export CFLAGS="-I/usr/include/openssl11" # Tell linkers where to find the libraries export LDFLAGS="-L/usr/lib64/openssl11"
If you want these settings to persist across sessions, add them to your ~/.bashrc file (or the activate script of your Python virtual environment, if you're using one).
Step 2: Install pyOpenSSL Against openssl11
Pre-built pyOpenSSL wheels usually link against the system's default older OpenSSL, so we need to force a source compilation to link against openssl11 instead.
First, if you have an existing pyOpenSSL installation, uninstall it:
pip uninstall -y pyopenssl
Then install it from source, disabling pre-built wheels:
pip install pyopenssl --no-binary :all:
Step 3: Verify the Linkage
To confirm everything worked, run this Python snippet:
import ssl import OpenSSL # Check the OpenSSL version used by Python's ssl module print("Python ssl module linked to:", ssl.OPENSSL_VERSION) # Check the version used directly by pyOpenSSL print("pyOpenSSL linked to:", OpenSSL.SSL.SSLeay_version(OpenSSL.SSL.SSLEAY_VERSION))
You should see output indicating OpenSSL 1.1.1 (or a newer minor release of 1.1.1) for both lines.
Important Notes
- Since
openssl11is intended for temporary use, avoid replacing the system's default OpenSSL library—this can break critical system tools that depend on the older version. - If you're using a virtual environment, adding the environment variables to the
activatescript of the env will ensure the linkage only applies to that specific environment, keeping your system Python untouched.
内容的提问来源于stack exchange,提问作者Mounya A

