Amazon Linux 2中Python3.10装OpenSSL1.1.1后pip仍报SSL模块不可用
在AWS Amazon Linux 2的EC2实例上,卸载预装的Python 3.7后手动安装了Python 3.10.10,同时将OpenSSL升级到1.1.1t版本。Python控制台可正常导入ssl模块,但执行pip操作时始终提示:
WARNING: pip is configured with locations that require TLS/SSL, however the ssl module in Python is not available.
导致无法更新pip或安装依赖库。
环境
- AWS Amazon Linux 2
- 本地主机:Windows10 64bit
- 连接工具:PowerShell v5.1.19041.2364
已执行操作
1. 安装前准备
已知Python 3.10依赖OpenSSL 1.1.1及以上版本,计划先升级OpenSSL。
2. 卸载原有Python 3.7
sudo yum update sudo yum remove python3.7 sudo rm cert-verification.cfg sudo rmdir python
3. 卸载原有OpenSSL
openssl version > OpenSSL 1.0.2k-fps sudo yum remove openssl sudo yum remove openssl-devel
4. 安装OpenSSL 1.1.1t
wget https://www.openssl.org/source/openssl-1.1.1t.tar.gz tar -xzv openssl-1.1.1t.tar.gz sudo yum install perl-core ./config --prefix=/usr/local/openssl-1.1.1t shared zlib make depend make make test sudo make install # sudo写入配置文件权限不足,切换root操作 su echo /usr/local/openssl-1.1.1t/lib > /etc/ld.so.conf.d/openssl-1.1.1t.conf exit sudo ldconfig # 更新PATH环境变量 nano /home/ec2-user/.bash_profile # 在PATH末尾添加:/usr/local/openssl-1.1.1t/bin source ./.bash_profile openssl version > OpenSSL 1.1.1t 7 Feb 2023
确认OpenSSL已升级成功。
5. 安装Python 3.10.10
wget https://www.python.org/ftp/python/3.10.10/Python-3.10.10.tar.xz tar -vxf Python-3.10.10.tar.xz sudo yum install gcc ./configure --enable-optimizations make sudo make install
安装完成后出现root用户使用pip的警告,未进行处理。
6. pip测试与问题触发
执行pip3 list时出现SSL相关错误提示:
pip3 list Package Version ----------- --------- pip 22.3.1 setuptools 65.5.0
WARNING: pip is configured with locations that require TLS/SSL, however the ssl module in Python is not available. There was a problem confirming the ssl certificate: HTTPSConnectionPool (host='pypi.org', port=443): Max retries exceeded with url: /simple/pip (Caused by SSLError("Can't connect to HTTPS URL because the SSL module is not available.")) - skipping.
7. 模块验证
openssl version显示为1.1.1t,系统无旧版本OpenSSL残留- Python控制台执行
import ssl无报错,模块可正常导入
原因与解决方法
核心原因
编译安装Python时未明确指定新OpenSSL的路径,导致Python虽能导入ssl模块,但pip运行时无法正确关联新的OpenSSL库,出现SSL不可用的错误;同时可能存在系统残留的旧依赖路径干扰。
解决步骤
- 清理原有Python编译文件
进入Python-3.10.10源码目录,执行:
make clean
- 重新配置Python编译参数,指定OpenSSL路径
执行configure时明确关联新安装的OpenSSL:
./configure --enable-optimizations \ --with-openssl=/usr/local/openssl-1.1.1t \ --with-openssl-rpath=auto
--with-openssl指定新OpenSSL的安装根目录,--with-openssl-rpath=auto让Python自动处理库路径,避免运行时找不到OpenSSL。
- 重新编译安装Python
make sudo make install
- 验证pip功能
重新打开终端(或执行source ~/.bash_profile),执行:
pip3 install --upgrade pip pip3 list
此时应能正常连接PyPI,不再出现SSL警告。
额外建议
- 避免直接卸载系统预装的Python和OpenSSL,推荐使用pyenv等版本管理工具安装多版本Python,减少系统依赖冲突。
- 尽量使用非root用户操作pip,通过
pip install --user或虚拟环境管理依赖,避免权限问题。
内容的提问来源于stack exchange,提问作者kazutaka

