You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

TensorFlow IO中Azure Blob Storage OAuth认证SSL证书异常问题

解决TensorFlow IO中C++访问Azure Blob Storage的SSL CA证书错误

Python代码通过OAuth令牌访问Azure Blob Storage可正常运行,但在TensorFlow IO环境下执行相同逻辑的C代码时,出现RuntimeError: Fail to get a new connection for: httpslogin.microsoftonline.com. Problem with the SSL CA cert (path? access rights?)错误,本地单独运行C代码无异常,设置TF_AZURE_STORAGE_USE_HTTP=1也无法解决。

核心原因

TensorFlow运行环境可能使用了独立的SSL配置或修改了环境变量,导致Azure Identity SDK无法识别系统默认的SSL CA证书路径;而本地单独运行C++程序时,能正常读取系统默认的证书配置。

解决步骤

1. 显式为Azure SDK指定SSL CA证书路径

在创建ClientSecretCredential时,通过SslOptions直接指定CA证书文件路径,确保Azure SDK能定位到正确的证书:

#include <Azure/Identity/ClientSecretCredential.hpp>
#include <Azure/Core/Http/SslOptions.hpp>

std::string tenantId = "your-tenant-id";
std::string activeDirectoryApplicationId = "your-app-id";
std::string activeDirectoryApplicationSecret = "your-app-secret";

// 配置SSL选项,指定CA证书路径
Azure::Core::Http::SslOptions sslOptions;
// 替换为实际路径:Linux下可填/etc/ssl/certs/ca-certificates.crt,Windows可指定系统证书文件路径
sslOptions.CaCertPath = "/path/to/ca-cert.pem";

auto clientSecretCredential = std::make_shared<Azure::Identity::ClientSecretCredential>(
    tenantId,
    activeDirectoryApplicationId,
    activeDirectoryApplicationSecret,
    Azure::Identity::ClientSecretCredentialOptions{},
    sslOptions
);

// 后续BlobContainerClient创建逻辑不变
std::string storageContainerUrl = "https://mystorage.blob.core.windows.net/mycontainer";
auto blobclient = std::make_shared<Azure::Storage::Blobs::BlobContainerClient>(
    storageContainerUrl,
    clientSecretCredential
);

2. 设置全局SSL证书环境变量

通过SSL_CERT_FILE环境变量指定CA证书文件,让TensorFlow和Azure SDK统一使用该证书:

  • 终端运行前配置:
    export SSL_CERT_FILE="/path/to/ca-cert.pem"
    
  • 若从Python调用TensorFlow IO的C++逻辑,可在Python代码中提前设置:
    import os
    os.environ['SSL_CERT_FILE'] = '/path/to/ca-cert.pem'
    

3. 调整TensorFlow IO编译配置(自行编译场景)

如果是自行编译TensorFlow IO,需确保编译时使用系统SSL库而非TensorFlow自带版本,添加编译参数:

bazel build --define=tf_io_use_system_ssl=true //tensorflow_io/...

此配置会让TensorFlow IO复用系统SSL配置,自动识别系统默认CA证书路径。

4. 关于HTTP模式的说明

TF_AZURE_STORAGE_USE_HTTP=1仅能让Blob Storage的访问改用HTTP,但Azure Identity SDK获取OAuth令牌时必须访问login.microsoftonline.com的HTTPS接口,因此该环境变量无法解决证书错误问题,必须通过SSL证书配置修复。

内容的提问来源于stack exchange,提问作者olaf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 17:54:31