Python requests基础命令执行报错,求问题原因与解决方法
Hey there, let's break down what's going on here and how to fix it!
The Problem
The error message clearly points to the core issue:
ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain
This means the website somedomain.xyz is using a self-signed SSL certificate instead of one issued by a globally trusted Certificate Authority (CA). By default, the requests library blocks connections to such sites—this is a security safeguard to prevent man-in-the-middle attacks, since self-signed certs don't have a trusted chain to confirm the site's legitimate identity.
Fix Options
1. Temporary Testing Fix (Not for Production!)
If you're just experimenting and don't need full security for this test, you can disable certificate verification entirely. You'll also want to suppress the warning that comes with this risky setting:
import requests from requests.packages.urllib3.exceptions import InsecureRequestWarning # Turn off the insecure request warning requests.packages.urllib3.disable_warnings(InsecureRequestWarning) result = requests.get("https://somedomain.xyz/start_page.html", verify=False) print(result.status_code)
⚠️ Critical Note: Never use this in production! Disabling verification strips away the SSL security layer, leaving your requests open to interception and tampering.
2. Proper Production Fix (Trust the Certificate)
The secure, long-term solution is to add the site's self-signed certificate to your trusted list:
- Export the certificate: Use your browser to visit
https://somedomain.xyz, download the certificate file (usually saved as.pemor.crtformat). - Reference the certificate in your request:
import requests # Replace "/path/to/your/certificate.pem" with the actual file path on your machine result = requests.get("https://somedomain.xyz/start_page.html", verify="/path/to/your/certificate.pem") print(result.status_code)
Alternatively, you can add the certificate to your system's trusted root CA store for global recognition:
- Windows: Use the Certificate Manager to import the certificate into the "Trusted Root Certification Authorities" store.
- Linux: Copy the certificate to
/usr/local/share/ca-certificates/, then runsudo update-ca-certificates. - macOS: Double-click the certificate file, add it to the "System" keychain, then mark it as trusted in the certificate settings.
Once added, Python will automatically recognize the certificate, and you won't need to specify the verify parameter anymore.
内容的提问来源于stack exchange,提问作者Tomáš

