不绕过SSL验证如何解决urllib出现[SSL: CERTIFICATE_VERIFY_FAILED]错误
urllib SSL证书验证失败根源解决方法
错误原因
该报错本质是Python运行环境依赖的根证书库中,缺少目标站点nominatim.openstreetmap.org证书链对应的可信根CA证书,或本地存储的根CA证书已过期。以下为无需跳过SSL校验的可行解决方案:
方案1:更新系统及Python的根证书库
- 如果你使用macOS系统,直接运行Python安装目录下的证书更新脚本即可:
打开终端执行/Applications/Python 3.x/Install Certificates.command(将3.x替换为你实际使用的Python版本号) - 如果你使用Linux发行版:
Debian/Ubuntu系执行sudo apt update && sudo apt install --reinstall ca-certificates
CentOS/RHEL系执行sudo yum reinstall ca-certificates - 如果你使用Windows系统:
打开系统设置的「管理计算机证书」,在「受信任的根证书颁发机构」中右键选择「所有任务-自动更新证书」,按照引导完成更新后重启Python运行环境即可。
- 如果你使用macOS系统,直接运行Python安装目录下的证书更新脚本即可:
方案2:手动指定可信证书发起请求
首先从浏览器访问https://nominatim.openstreetmap.org,导出站点证书链的根CA证书保存为osm_root.pem文件,发起请求时显式传入带可信证书的SSL上下文即可,代码示例:import urllib.request import ssl import json gojson = 'https://nominatim.openstreetmap.org/details.php?osmtype=W&osmid=17025436&class=highway&addressdetails=1&hierarchy=0&group_hierarchy=1&format=json&polygon_geojson=1' # 创建指定可信根证书的SSL上下文 context = ssl.create_default_context(cafile="./osm_root.pem") res_body = urllib.request.urlopen(gojson, context=context).read()方案3:使用certifi维护的通用根证书库
先执行pip install certifi安装维护了通用可信根证书的第三方库,请求时传入certifi提供的根证书文件路径即可:import urllib.request import ssl import json import certifi gojson = 'https://nominatim.openstreetmap.org/details.php?osmtype=W&osmid=17025436&class=highway&addressdetails=1&hierarchy=0&group_hierarchy=1&format=json&polygon_geojson=1' context = ssl.create_default_context(cafile=certifi.where()) res_body = urllib.request.urlopen(gojson, context=context).read()
内容的提问来源于stack exchange,提问作者trey hannam
相关产品推荐
相关产品推荐

