Windows 10下使用git和pip出现SSL解密错误求助
Solutions for SSL Decryption Failed Errors on Windows 10 (pip & git)
The following steps address the [SSL: DECRYPTION_FAILED_OR_BAD_RECORD_MAC] error in pip and the corresponding SSL_read error in git, after standard fixes (updating OpenSSL, certificate installs, network changes) have failed:
Temporarily disable SSL verification (insecure, testing only)
- For pip: Append trusted host flags to your install command:
pip3 install pillow --user --trusted-host pypi.org --trusted-host files.pythonhosted.org - For git: Disable global SSL verification (re-enable after testing):
Re-enable with:git config --global http.sslVerify falsegit config --global http.sslVerify true
- For pip: Append trusted host flags to your install command:
Check antivirus/Windows Defender interference
- Temporarily disable real-time protection in Windows Defender or any third-party antivirus software. SSL inspection features often cause decryption mismatches. If the error goes away, add exceptions for Python/git executables or disable SSL inspection for these tools.
Reset Windows network settings
- Go to Settings > Network & Internet > Status > Network reset. This resets network adapters, Winsock, and TCP/IP settings to default. Restart your system after the reset and test again.
Use a Python distribution with bundled OpenSSL
- Install Anaconda or Miniconda, which includes its own OpenSSL library. This avoids dependency issues with the system-wide OpenSSL installation.
Switch git to SSH transport
- Generate an SSH key pair (using
ssh-keygenin Git Bash) and add the public key to your Git host (GitHub/GitLab/etc.). Clone repositories using the SSH URL instead of HTTPS to bypass SSL-related issues:git clone git@github.com:username/repository.git
- Generate an SSH key pair (using
Update git to the latest version
- Download and install the newest git release for Windows. The bundled SSL library in older git versions may have compatibility issues with modern servers.
Inspect hosts file for rogue entries
- Open
C:\Windows\System32\drivers\etc\hostswith admin privileges. Check for any unexpected entries pointing to PyPI or Git host domains that might redirect traffic. Remove any suspicious lines and save the file.
- Open
Content sourced from Stack Exchange, question author Dennis Hvel
相关产品推荐
相关产品推荐

