You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何获取SSL验证所需的根证书与Alpha SSL中间证书?

解决证书链缺失Alpha SSL中间证书的自动验证问题

根本解决方案:让服务器配置完整证书链

  • 多数情况下客户端缺少中间证书,是因为服务器未返回完整证书链(服务器证书 + Alpha SSL中间证书)。正常服务端应发送完整链,客户端即可通过certifi自带的GlobalSign根证书完成验证,无需手动维护中间证书。这是最合规的方案,证书更新由服务端负责,客户端无需干预。

客户端自动管理证书链(服务端无法修改时)

如果服务端无法调整配置,可以通过以下方式自动获取并验证中间证书,避免手动下载:

方法1:从服务器证书链中提取中间证

直接从目标服务器返回的证书链中提取中间证书,确保与服务器当前使用的证书同步,自动适配更新:

import certifi
import ssl
import socket
from cryptography import x509
from cryptography.hazmat.backends import default_backend

def get_valid_intermediate(domain, port=443):
    # 创建临时上下文获取服务器证书链
    temp_context = ssl.create_default_context()
    temp_context.check_hostname = False
    temp_context.verify_mode = ssl.CERT_NONE
    
    with socket.create_connection((domain, port)) as sock:
        with temp_context.wrap_socket(sock, server_hostname=domain) as ssock:
            cert_chain_bin = ssock.getpeercert(binary_form=True)
            certs = x509.load_pem_x509_certificates(cert_chain_bin, default_backend())
            
            # 筛选中间证书(非自签、 issuer与subject不同)
            intermediates = [c for c in certs if not c.is_self_signed() and c.subject != c.issuer]
            if not intermediates:
                return None
            
            # 验证中间证由GlobalSign根证签名(确保可信)
            root_cert_store = ssl.SSLContext().get_ca_certs(binary_form=True)
            root_certs = [x509.load_der_x509_cert(rc, default_backend()) for rc in root_cert_store]
            
            for root in root_certs:
                if root.subject == intermediates[0].issuer:
                    try:
                        intermediates[0].verify(root.public_key())
                        return intermediates[0].public_bytes(x509.Encoding.PEM)
                    except:
                        continue
    return None

# 使用示例
target_domain = "your-server-domain.com"
intermediate_pem = get_valid_intermediate(target_domain)

if intermediate_pem:
    # 合并certifi根证与中间证
    with open(certifi.where(), "rb") as f:
        combined_certs = f.read() + intermediate_pem
    
    # 生成临时CA文件用于验证
    temp_ca_path = "/tmp/combined_ca.pem"
    with open(temp_ca_path, "wb") as f:
        f.write(combined_certs)
    
    # 用合并后的证书发起请求(以requests为例)
    import requests
    response = requests.get(f"https://{target_domain}", verify=temp_ca_path)

方法2:使用系统级证书存储

多数操作系统(Linux/macOS的系统证书库、Windows证书存储)已包含常用中间证书(包括Alpha SSL),让应用使用系统证书而非certifi的,即可自动享受系统的证书更新:

import os
import requests

# Linux/macOS 指定系统CA文件路径
os.environ["REQUESTS_CA_BUNDLE"] = "/etc/ssl/certs/ca-certificates.crt"

# Windows 可指定系统CA文件或直接依赖系统证书存储
# os.environ["REQUESTS_CA_BUNDLE"] = "C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Certificates\\My\\Root"

# 发起请求时自动使用系统证书验证
response = requests.get("https://your-server-domain.com")

内容的提问来源于stack exchange,提问作者Aruna Priyadarshini

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 20:50:29