You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS EC2实例访问GeoPy的Nominatim API出现SSL错误如何解决?

错误根因

该SSL证书验证失败和你调整的入站安全组规则无关:你调用外部API属于出站请求,EC2默认安全组出站规则默认允许所有流量外出,无需额外调整入站规则。报错的核心是你的EC2实例系统根证书库过期,或是Python依赖的证书文件未包含目标域名的SSL证书签发机构信息。

可行解决方案
  • 先更新EC2实例的系统根证书库:
    若实例操作系统为Amazon Linux 2/CentOS/RHEL,执行:
    sudo yum update ca-certificates
    若实例操作系统为Ubuntu/Debian,执行:
    sudo apt update && sudo apt install --reinstall ca-certificates
  • 再更新Python的证书依赖与geopy版本:
    pip install --upgrade certifi geopy
  • 若上述操作仍无法解决,可临时在初始化Nominatim时指定自定义SSL上下文跳过验证(仅测试使用,生产环境不推荐),修改get_coord函数代码如下:
    import ssl
    from geopy.adapters import URLLibAdapter
    
    def get_coord(zip_code):
        # 构造跳过SSL验证的上下文
        ssl_ctx = ssl.create_default_context()
        ssl_ctx.check_hostname = False
        ssl_ctx.verify_mode = ssl.CERT_NONE
        
        geolocator = Nominatim(
            user_agent="GCD Data Client",
            adapter_factory=URLLibAdapter,
            ssl_context=ssl_ctx
        )
        location = geolocator.geocode({"postalcode": zip_code, "country": "US"}, exactly_one = True)
        in_lat = location.latitude
        in_lon = location.longitude
        return in_lat, in_lon
    
额外优化提示

你代码中的get_params函数定义时写了self参数,但实际调用时是作为普通函数使用,没有绑定类实例,建议删掉这个多余的self参数避免后续出现调用错误。另外公共Nominatim接口有严格的请求频率限制,生产环境建议自建Nominatim实例或使用商用地理编码服务,避免被限流。

内容的提问来源于stack exchange,提问作者Zach Rieck

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.01 14:15:04