You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用服务主体访问Azure Blob存储报错unable to get local issuer certificate

问题原因

报错发生在Azure AD身份认证获取令牌阶段,你此前配置的connection_verify=False和代理参数仅作用于Azure存储服务的请求,未覆盖认证请求环节,因此SSL验证依然失败。另外你代码中未定义session变量就直接传入BlobServiceClient,会额外触发命名错误。

修复步骤
  • 给ClientSecretCredential传入代理配置和禁用SSL验证参数,保证认证环节请求可正常通过代理
  • 移除BlobServiceClient初始化时未定义的session参数
  • 可选:全局禁用SSL不安全请求警告,避免控制台输出冗余告警
  • 如果运行时提示ClientSecretCredential不支持proxies或verify参数,执行命令升级依赖库:pip install --upgrade azure-identity azure-storage-blob
修正后的完整代码
import os
import urllib3
from azure.identity import ClientSecretCredential
from azure.storage.blob import BlobServiceClient

# 禁用SSL不安全请求警告
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)

os.environ["HTTP_PROXY"] = "**********"
os.environ["HTTPS_PROXY"] = "**********"

proxies = {
    "http": "*****************",
    "https": "*****************"
}

# 你的Azure订阅的租户ID
TENANT_ID = "e4c9****-****-****-****-230b****57fb"
# 你的服务主体应用ID
CLIENT = "3bee****-****-****-****-b0b8****f7a4"
# 你的服务主体密码
KEY = "*******************"
ACCOUNT_NAME = "storagetest789"
CONTAINER_NAME = "newcontainer"

# 认证环节传入代理和禁用SSL验证配置
credentials = ClientSecretCredential(
    TENANT_ID, 
    CLIENT, 
    KEY,
    proxies=proxies,
    verify=False
)

# 移除未定义的session参数
blobService = BlobServiceClient(
    "https://{}.blob.core.windows.net".format(ACCOUNT_NAME), 
    credential=credentials, 
    proxies=proxies, 
    connection_verify=False
)

print("\nList blobs in the container")
container = blobService.get_container_client(CONTAINER_NAME)
for blob in container.list_blobs():
    print("\t Blob name: " + blob.name)

print("\nOutput test.txt")
blob = container.get_blob_client("test.txt")
print(blob.download_blob().readall())

内容的提问来源于stack exchange,提问作者laotsien

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.26 06:15:01