为何安装fsspec、et-xmlfile等Python包时出现OSError?
问题背景
通过requirements.txt安装Python包时,本地包安装正常,但fsspec==2022.2.0、et-xmlfile==1.1.0等公共包安装失败,返回SSL证书验证错误:
ERROR: Could not install packages due to an OSError: HTTPSConnectionPool(host='files.pythonhosted.org', port=443): Max retries exceeded with url: /packages/96/c2/3dd434b0108730014f1b96fd286040dc3bcb70066346f7e01ec2ac95865f/et_xmlfile-1.1.0-py3-none-any.whl (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)')))
其他包(如cramjam)安装正常,且已尝试使用上述两个包的最新版本。
解决方法
1. 临时跳过SSL验证(应急方案)
执行安装命令时添加--trusted-host参数,指定信任PyPI相关域名:
pip install -r requirements.txt --trusted-host pypi.org --trusted-host files.pythonhosted.org
注:此方法仅适合临时应急,长期使用会降低安全性。
2. 更新系统CA证书
证书验证失败通常是本地根证书库过期或缺失导致,根据操作系统更新证书:
- Windows:打开Windows更新,检查并安装所有可选更新(包含证书更新);或手动导入缺失的根证书。
- macOS:找到对应Python版本的证书安装脚本并执行(以Python 3.10为例):
/Applications/Python\ 3.10/Install\ Certificates.command - Linux(Debian/Ubuntu):更新证书包并刷新证书库:
sudo apt-get update && sudo apt-get install -y ca-certificates sudo update-ca-certificates
3. 指定Python使用的证书文件
如果系统证书无法正常读取,可手动指定证书路径:
- Linux/macOS:设置环境变量后执行安装:
export REQUESTS_CA_BUNDLE=/etc/ssl/certs/ca-certificates.crt pip install -r requirements.txt - Windows:设置系统环境变量
REQUESTS_CA_BUNDLE为本地证书文件路径,或直接在命令中指定:pip install -r requirements.txt --cert "C:\path\to\ca-certificate.crt"
4. 检查代理设置
若使用代理服务器,可能是代理的证书未被系统信任:
- 临时关闭代理后重试安装;
- 将代理的根证书导入系统信任证书列表。
内容的提问来源于stack exchange,提问作者ewanzhang15

