使用python-oracledb Thin Client连接Oracle自治数据库遇DPY-6005错误
Python oracledb连接Oracle ATP/ADP证书验证失败问题解决
问题现象
使用Python oracledb thin客户端连接21c ATP和19c ADP(免费层级,已配置ACL为当前地址,启用TLS且mTLS设为“不需要”,连接字符串包含ssl_server_dn_match=yes)时,触发证书验证失败错误:
OperationalError: DPY-6005: cannot connect to database. Connection
failed with "[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify
failed: self signed certificate in certificate chain (_ssl.c:1131)"
环境信息
- 数据库:ATP 21c、ADP 19c
- Python库:oracledb 1.2.1(曾尝试1.2.0、1.1.1,均无效)
- 运行环境:Python 3.10.4/3.8.10(Mac OS)
测试代码
import oracledb # 从ATP连接页面复制的字符串 cs='''(description= (retry_count=20)(retry_delay=3)(address=(protocol=tcps)(port=1521)(host=adb.uk-london-1.oraclecloud.com))(connect_data=(service_name=xxxx.adb.oraclecloud.com))(security=(ssl_server_dn_match=yes)))''' connection = oracledb.connect(user="admin", password="<password>", dsn=cs) with connection.cursor() as cursor: try: sql = """select systimestamp from dual""" for r in cursor.execute(sql): print(r) except oracledb.Error as e: error, = e.args print(error.message) print(sql) if (error.offset): print('^'.rjust(error.offset+1, ' '))
解决方法
1. 手动指定Oracle根证书
Mac系统下Python默认CA库不包含Oracle云的根证书,需手动配置:
- 从ATP/ADP的连接页面下载客户端凭据包,解压后提取PEM格式的根证书
- 将证书保存到本地路径,比如
/Users/yourname/oracle_certs/root.crt - 修改连接配置:
# 方式一:在连接字符串中添加证书路径 cs='''(description= (retry_count=20)(retry_delay=3)(address=(protocol=tcps)(port=1521)(host=adb.uk-london-1.oraclecloud.com))(connect_data=(service_name=xxxx.adb.oraclecloud.com))(security=(ssl_server_dn_match=yes)(ssl_cert="/Users/yourname/oracle_certs/root.crt")))''' # 方式二:通过connect参数指定 connection = oracledb.connect( user="admin", password="<password>", dsn=cs, ssl_cert="/Users/yourname/oracle_certs/root.crt" )
2. 临时禁用证书验证(仅测试环境)
如果是测试场景,可临时关闭证书验证(生产环境禁止使用):
# 修改连接字符串的security部分 cs='''(description= (retry_count=20)(retry_delay=3)(address=(protocol=tcps)(port=1521)(host=adb.uk-london-1.oraclecloud.com))(connect_data=(service_name=xxxx.adb.oraclecloud.com))(security=(ssl_server_dn_match=no)(ssl_verify_server_cert=no)))'''
3. 更新Python CA证书库
通过certifi库更新系统CA证书:
- 安装certifi:
pip install certifi - 在代码开头添加:
import certifi import os os.environ['SSL_CERT_FILE'] = certifi.where()
内容的提问来源于stack exchange,提问作者Babak Tourani
相关产品推荐
相关产品推荐

