企业Windows机器升级pip或安装Python包遇SSL证书验证失败错误
环境信息
- 系统:企业所属Windows机器
- Python版本:3.11.2
- Pip版本:22.3.1(最新为23.1)
- Python本地目录:
C:\Users\{User}\AppData\Local\Programs\Python\Python311
问题现象
执行pip install pandas或升级pip时,触发SSL证书验证错误,完整错误信息如下:
pip : WARNING: Retrying (Retry(total=4, connect=None, read=None, redirect=None, status=None)) after connection broken by
'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate
(_ssl.c:992)'))': /simple/pandas/
At line:1 char:1
- pip install pandas
+ CategoryInfo : NotSpecified: (WARNING: Retryi.../simple/pandas/:String) [], RemoteException + FullyQualifiedErrorId : NativeCommandErrorWARNING: Retrying (Retry(total=3, connect=None, read=None, redirect=None, status=None)) after connection broken by
'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate
(_ssl.c:992)'))': /simple/pandas/
WARNING: Retrying (Retry(total=2, connect=None, read=None, redirect=None, status=None)) after connection broken by
'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate
(_ssl.c:992)'))': /simple/pandas/
WARNING: Retrying (Retry(total=1, connect=None, read=None, redirect=None, status=None)) after connection broken by
'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate
(_ssl.c:992)'))': /simple/pandas/
WARNING: Retrying (Retry(total=0, connect=None, read=None, redirect=None, status=None)) after connection broken by
'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate
(_ssl.c:992)'))': /simple/pandas/
Could not fetch URL https://pypi.org/simple/pandas/: There was a problem confirming the ssl certificate: HTTPSConnectionPool(host='pypi.org', port=443):
Max retries exceeded with url: /simple/pandas/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify faile
d: unable to get local issuer certificate (_ssl.c:992)'))) - skipping
ERROR: Could not find a version that satisfies the requirement pandas (from versions: none)
ERROR: No matching distribution found for pandas
Could not fetch URL https://pypi.org/simple/pip/: There was a problem confirming the ssl certificate: HTTPSConnectionPool(host='pypi.org', port=443): Max
retries exceeded with url: /simple/pip/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:992)'))) - skipping
WARNING: There was an error checking the latest version of pip.
已尝试的无效方案
- 验证浏览器可正常访问相关链接,排除管理员拦截可能
- 移除环境变量PATH中Python目录的末尾斜杠
- 执行
curl https://bootstrap.pypa.io/get-pip.py -o get-pip.py后运行python get-pip.py,仍报错 - 验证浏览器可访问PyPI相关域名
- 尝试查看本地证书列表,但未理解操作步骤
- 下载最新certifi文件,推测已是最新版本
- 查阅大量同类问题,尝试的方案均无效
- 企业机器限制,无法使用跳过SSL证书验证的选项
可行解决方案
1. 配置pip适配企业代理与内部证书
企业网络基本都走代理,且有专属CA证书,需将这些信息配置给pip:
- 向IT部门获取企业代理地址(如
http://proxy.xxx.com:8080)和内部CA证书文件(通常为.crt或.pem格式) - 在用户目录下创建
pip文件夹,路径为C:\Users\{User}\AppData\Roaming\pip,然后新建pip.ini文件,写入以下内容(替换占位符为实际信息):
[global] proxy = 你的企业代理地址 cert = CA证书的本地绝对路径
2. 让Python使用系统证书库
Python默认自带certifi证书库,而企业机器的系统已安装内部CA证书,可配置Python调用系统证书:
- 设置环境变量
REQUESTS_CA_BUNDLE,值可设为系统证书存储路径(Windows一般为C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates),或直接指向IT提供的CA证书文件 - 也可修改Python自带的certifi证书:找到
C:\Users\{User}\AppData\Local\Programs\Python\Python311\Lib\site-packages\certifi\cacert.pem,将企业CA证书内容复制到该文件末尾(可能需要管理员权限,可联系IT协助)
3. 联系企业IT部门确认配置
若上述方案无效,直接找IT部门核实:
- PyPI相关域名的访问权限与代理设置是否正常
- 内部CA证书是否已正确部署到机器的系统证书存储中
- 是否需要将Python加入企业安全白名单
内容的提问来源于stack exchange,提问作者PowerUser

