使用AWS-shell向AWS S3存储桶传图片遇SSL验证错误求助
解决AWS S3上传时的SSL验证失败问题
使用boto3上传文件到S3存储桶时出现以下SSL验证错误:
botocore.exceptions.SSLError: SSL validation failed for https://s3bucketname.s3.amazonaws.com/index/Wayne_Rooney.jpg [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)
可以通过以下几种方式解决:
更新本地CA证书库
这个错误大多是本地系统缺少必要的SSL根证书导致的,先试试更新系统的CA证书:- Ubuntu/Debian系统:运行
sudo apt-get update && sudo apt-get install ca-certificates - CentOS/RHEL系统:运行
sudo yum update ca-certificates - Windows系统:通过Windows更新安装最新根证书,或者手动下载并安装缺失的根证书。
- Ubuntu/Debian系统:运行
手动指定CA证书路径给boto3
系统证书更新后仍无法解决的话,初始化boto3资源时手动指定CA证书文件路径:import boto3 from botocore.config import Config # 替换为你的系统CA证书路径,比如Ubuntu用/etc/ssl/certs/ca-certificates.crt config = Config(ca_bundle='/path/to/ca_cert.pem') s3 = boto3.resource('s3', config=config) images=[('Micheal_Jordan.jpg','Micheal Jordan'), ('Wayne_Rooney.jpg','Wayne Rooney') ] for image in images: file = open(image[0],'rb') object = s3.Object('famouspersons-images','index/'+ image[0]) ret = object.put(Body=file, Metadata={'FullName':image[1]})临时禁用SSL验证(仅测试环境用)
要是只是测试场景,可临时关闭SSL验证,但生产环境绝对不能用,存在安全风险:import boto3 from botocore.config import Config config = Config(verify=False) s3 = boto3.resource('s3', config=config) # 后续上传代码保持不变检查网络代理配置
如果机器通过代理访问网络,可能是代理拦截了SSL连接导致验证失败。要确保代理配置正确,或者设置绕过代理访问S3服务。
内容的提问来源于stack exchange,提问作者Archish J
相关产品推荐
相关产品推荐

