Python通过Proton Bridge连接ProtonMail遇SSL版本错误求助
问题
尝试用Python的imaplib库通过Proton Bridge登录ProtonMail账户,目标是统计未读邮件数量。在Pop!_OS 22.04 LTS(内核版本5.19.0-76051900-generic)运行代码时,出现错误:
ssl.SSLError: [SSL: WRONG_VERSION_NUMBER] wrong version number (_ssl.c:997)
使用的代码如下:
#!/usr/bin/python3 import imaplib import ssl usern="username" passw="password" bridge_certificate="cert.pem" sslctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT) sslctx.options &= ~ssl.OP_NO_SSLv3 sslctx.load_verify_locations(cafile=bridge_certificate) sslctx.verify_mode = ssl.CERT_OPTIONAL sslctx.check_hostname = False count = 0 imap = imaplib.IMAP4_SSL("localhost", 1143, ssl_context=sslctx) imap.login(usern, passw) imap.select('INBOX') status, response = imap.search(None, '(UNSEEN)') if status == 'OK': for num in response[0].split(): count=count+1 print(count) imap.close() imap.logout()
错误原因分析
这个错误核心是SSL版本不匹配,具体原因有两点:
- Proton Bridge的1143端口是明文IMAP端口,不需要直接用SSL/TLS连接,你用
IMAP4_SSL去连接这个端口相当于给明文连接套了SSL层,导致协议版本不兼容。 - 代码中手动开启了已废弃的SSLv3协议,现代服务包括Proton Bridge都不再支持该协议,进一步加剧了版本不匹配问题。
解决方法
方法一:明文连接后升级TLS(推荐)
Proton Bridge的1143端口为明文端口,应先建立普通IMAP连接,再通过starttls升级为加密连接:
#!/usr/bin/python3 import imaplib import ssl usern="username" passw="password" bridge_certificate="cert.pem" sslctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT) sslctx.load_verify_locations(cafile=bridge_certificate) sslctx.verify_mode = ssl.CERT_REQUIRED sslctx.check_hostname = True count = 0 # 建立明文IMAP连接 imap = imaplib.IMAP4("localhost", 1143) # 升级到TLS加密 imap.starttls(ssl_context=sslctx) imap.login(usern, passw) imap.select('INBOX') status, response = imap.search(None, '(UNSEEN)') if status == 'OK': count = len(response[0].split()) if response[0] else 0 print(count) imap.close() imap.logout()
方法二:直接连接SSL端口
Proton Bridge默认提供993作为IMAP SSL端口,可直接用IMAP4_SSL连接:
#!/usr/bin/python3 import imaplib import ssl usern="username" passw="password" bridge_certificate="cert.pem" sslctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT) sslctx.load_verify_locations(cafile=bridge_certificate) sslctx.verify_mode = ssl.CERT_REQUIRED sslctx.check_hostname = True count = 0 # 连接SSL端口993 imap = imaplib.IMAP4_SSL("localhost", 993, ssl_context=sslctx) imap.login(usern, passw) imap.select('INBOX') status, response = imap.search(None, '(UNSEEN)') if status == 'OK': count = len(response[0].split()) if response[0] else 0 print(count) imap.close() imap.logout()
额外优化说明
- 移除了启用SSLv3的代码,避免使用不安全协议
- 将证书验证模式改为
ssl.CERT_REQUIRED,保证连接安全性 - 简化未读邮件计数逻辑,用
len()统计更高效
内容的提问来源于stack exchange,提问作者atammayata
相关产品推荐
相关产品推荐

