使用Selenium Firefox打开Outlook遇HSTS相关InsecureCertificateException求助
解决Selenium Firefox打开Outlook时的InsecureCertificateException(HSTS相关)
问题描述
使用Selenium操控Firefox打开https://outlook.live.com/时触发InsecureCertificateException,提示受HSTS安全策略限制无法连接,相同代码操作Gmail可正常运行。终端异常栈如下:
Traceback (most recent call last): File "d:\Code\Python\plugins-olek-test\initializer.py", line 313, in start_driver driver.get(url) File "C:\Users\IT PLANET\AppData\Local\Programs\Python\Python39\lib\site-packages\selenium\webdriver\remote\webdriver.py", line 449, in get self.execute(Command.GET, {"url": url}) File "C:\Users\IT PLANET\AppData\Local\Programs\Python\Python39\lib\site-packages\selenium\webdriver\remote\webdriver.py", line 440, in execute self.error_handler.check_response(response) File "C:\Users\IT PLANET\AppData\Local\Programs\Python\Python39\lib\site-packages\selenium\webdriver\remote\errorhandler.py", line 245, in check_response raise exception_class(message, screen, stacktrace) selenium.common.exceptions.InsecureCertificateException: Message: Stacktrace: RemoteError@chrome://remote/content/shared/RemoteError.sys.mjs:8:8 WebDriverError@chrome://remote/content/shared/webdriver/Errors.sys.mjs:180:5 InsecureCertificateError@chrome://remote/content/shared/webdriver/Errors.sys.mjs:301:5 checkReadyState@chrome://remote/content/marionette/navigate.sys.mjs:58:24 onNavigation@chrome://remote/content/marionette/navigate.sys.mjs:329:39 emit@resource://gre/modules/EventEmitter.sys.mjs:154:20 receiveMessage@chrome://remote/content/marionette/actors/MarionetteEventsParent.sys.mjs:35:25
问题原因
你使用了seleniumwire,它会通过代理拦截HTTPS请求并生成自签名证书重加密流量。Outlook的HSTS策略极为严格,拒绝信任未被系统/浏览器认可的自签名证书;而Gmail在证书兼容逻辑上更宽松,因此能正常运行。
解决方案
方案1:让Firefox信任SeleniumWire的CA证书(推荐,安全且保留抓包功能)
- 找到SeleniumWire的CA证书路径:
- Windows:
C:\Users\<你的用户名>\.seleniumwire\ca.crt - Linux/macOS:
~/.seleniumwire/ca.crt
- Windows:
- 手动导入证书到Firefox配置文件:
- 打开Firefox,进入
about:preferences#privacy - 找到「证书」→「查看证书」→「证书机构」→「导入」,选中上述CA证书文件,勾选「信任由此证书机构标识的网站」后确认
- 打开Firefox,进入
- 代码中保持使用该配置文件即可
方案2:调整Firefox偏好绕过证书检查(应急用,不推荐生产环境)
在FirefoxOptions中添加以下偏好设置,强制Firefox忽略证书错误:
from seleniumwire import webdriver from selenium.webdriver.chrome.service import Service from webdriver_manager.firefox import GeckoDriverManager import sys URL = 'https://outlook.live.com/' firefox_options = webdriver.FirefoxOptions() path_to_firefox_profile = "output_files\\firefox\\xlycfcyp.default-release" # 添加证书相关偏好 firefox_options.set_preference("security.enterprise_roots.enabled", True) firefox_options.set_preference("ssl.override_security_restrictions", True) firefox_options.set_preference("browser.ssl_override_behavior", 1) # 1表示忽略证书错误 firefox_options.set_preference("dom.webdriver.enabled", False) firefox_options.set_preference('useAutomationExtension', False) firefox_options.set_preference("general.useragent.override", 'Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:89.0) Gecko/20100101 Firefox/89.0') # 用Options加载配置文件,替代旧的FirefoxProfile用法 firefox_options.add_argument(f"-profile {path_to_firefox_profile}") firefox_options.add_argument("--width=1400") firefox_options.add_argument("--height=1000") driver_installation = GeckoDriverManager().install() service = Service(driver_installation) if sys.platform == 'win32': from subprocess import CREATE_NO_WINDOW service.creationflags = CREATE_NO_WINDOW driver = webdriver.Firefox(options=firefox_options, service=service) driver.get(URL)
方案3:禁用SeleniumWire代理(不需要抓包时使用)
如果不需要抓包功能,直接改用普通Selenium Firefox驱动:
from selenium import webdriver from selenium.webdriver.chrome.service import Service from webdriver_manager.firefox import GeckoDriverManager import sys URL = 'https://outlook.live.com/' firefox_options = webdriver.FirefoxOptions() path_to_firefox_profile = "output_files\\firefox\\xlycfcyp.default-release" firefox_options.set_preference("dom.webdriver.enabled", False) firefox_options.set_preference('useAutomationExtension', False) firefox_options.set_preference("general.useragent.override", 'Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:89.0) Gecko/20100101 Firefox/89.0') firefox_options.add_argument(f"-profile {path_to_firefox_profile}") firefox_options.add_argument("--width=1400") firefox_options.add_argument("--height=1000") driver_installation = GeckoDriverManager().install() service = Service(driver_installation) if sys.platform == 'win32': from subprocess import CREATE_NO_WINDOW service.creationflags = CREATE_NO_WINDOW driver = webdriver.Firefox(options=firefox_options, service=service) driver.get(URL)
内容的提问来源于stack exchange,提问作者farhan jatt
相关产品推荐
相关产品推荐

