Python连接WSS时证书验证失败求助(已更新certifi仍无效)
Let's break down why you're hitting this error and walk through actionable fixes:
Why this happens
The ssl.SSLCertVerificationError you're seeing means Python's SSL module can't locate the correct root certificates to validate the server's certificate chain. Even though you updated certifi, your Python installation (specifically the python.org build on macOS, which your file path indicates) might not be configured to use certifi's certificate store by default.
Fix 1: Manually point websockets to certifi's certificates
You can create a custom SSL context that uses certifi's root certificates and pass it directly to websockets.connect. Here's your modified code:
import asyncio import logging import ssl import certifi import websockets from websockets import WebSocketClientProtocol logging.basicConfig(level=logging.INFO) async def consumer_handler(websocket: WebSocketClientProtocol) -> None: async for message in websocket: log_message(message) async def consume(hostname: str) -> None: websocket_resource_url = f'wss://{hostname}' # Create SSL context using certifi's curated certificates ssl_context = ssl.create_default_context() ssl_context.load_verify_locations(certifi.where()) async with websockets.connect(websocket_resource_url, ssl=ssl_context) as websocket: await consumer_handler(websocket) def log_message(message: str) -> None: logging.info(f'Message: {message}') if __name__ == '__main__': asyncio.run(consume(hostname='echo.websocket.org'))
Fix 2: Fix macOS Python certificate configuration system-wide
Python builds from python.org on macOS often ship with incomplete certificate setups. Run the built-in certificate installation script to resolve this for all your Python projects:
/Library/Frameworks/Python.framework/Versions/3.7/bin/python3.7 /Applications/Python\ 3.7/Install\ Certificates.command
This script automatically configures Python to use certifi's certificates, eliminating the root cause of the verification failure.
Fix 3: Disable certificate verification (only for testing!)
If you just need to test connectivity and don't care about security (never use this in production), you can skip certificate validation entirely:
async with websockets.connect(websocket_resource_url, ssl=False) as websocket:
This bypasses all certificate checks, which leaves your connection vulnerable to man-in-the-middle attacks—use it only for quick debugging.
Why updating certifi alone didn't work
Certifi provides a trusted set of root certificates, but Python's default SSL context doesn't always pick it up automatically on macOS. The fixes above either manually link certifi's certificates to your websocket connection or configure Python to use them by default.
内容的提问来源于stack exchange,提问作者Thanasis

