You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决连接Elasticsearch时的SSL自签名证书验证失败错误?

解决Elasticsearch TLS证书验证失败问题

先修正你代码中的笔误:第二、三段代码里的127.0.0.1t是输入错误,改为127.0.0.1或localhost才能正常连接。

针对你遇到的CERTIFICATE_VERIFY_FAILED错误,以下是可行的解决方式:

方式一:关闭SSL验证(测试环境适用)

确保正确导入ssl模块,配置SSL上下文并关闭验证:

import ssl
from elasticsearch import Elasticsearch
from ssl import create_default_context

ssl_context = create_default_context()
ssl_context.check_hostname = False
ssl_context.verify_mode = ssl.CERT_NONE

es = Elasticsearch(
    hosts=[{'host': 'localhost', 'port': 9200}],
    scheme="https",
    verify_certs=False,
    ssl_context=ssl_context,
    basic_auth=("elastic", "elastic")
)

或者用更简洁的写法,直接通过客户端参数关闭验证:

from elasticsearch import Elasticsearch

es = Elasticsearch(
    "https://localhost:9200",
    basic_auth=("elastic", "elastic"),
    verify_certs=False,
    ssl_show_warn=False
)

方式二:使用官方CA证书(生产环境推荐)

Elasticsearch 8.x默认生成自签名CA证书,你可以用它完成合法验证:

  1. 找到Elasticsearch安装目录下的config/certs/http_ca.crt文件
  2. 在代码中指定证书的实际路径:
from elasticsearch import Elasticsearch

es = Elasticsearch(
    "https://localhost:9200",
    basic_auth=("elastic", "elastic"),
    ca_certs="D:/elasticsearch-8.4.0/config/certs/http_ca.crt"  # 替换为你的本地证书路径
)

你的环境信息:

  • Windows 10
  • Elasticsearch 8.4.0
  • Python 3.10
  • PyCharm

内容的提问来源于stack exchange,提问作者오세창

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 22:10:31