AWS EC2实例访问GeoPy的Nominatim API出现SSL错误如何解决?
错误根因
该SSL证书验证失败和你调整的入站安全组规则无关:你调用外部API属于出站请求,EC2默认安全组出站规则默认允许所有流量外出,无需额外调整入站规则。报错的核心是你的EC2实例系统根证书库过期,或是Python依赖的证书文件未包含目标域名的SSL证书签发机构信息。
可行解决方案
- 先更新EC2实例的系统根证书库:
若实例操作系统为Amazon Linux 2/CentOS/RHEL,执行:sudo yum update ca-certificates
若实例操作系统为Ubuntu/Debian,执行:sudo apt update && sudo apt install --reinstall ca-certificates - 再更新Python的证书依赖与geopy版本:
pip install --upgrade certifi geopy - 若上述操作仍无法解决,可临时在初始化Nominatim时指定自定义SSL上下文跳过验证(仅测试使用,生产环境不推荐),修改
get_coord函数代码如下:import ssl from geopy.adapters import URLLibAdapter def get_coord(zip_code): # 构造跳过SSL验证的上下文 ssl_ctx = ssl.create_default_context() ssl_ctx.check_hostname = False ssl_ctx.verify_mode = ssl.CERT_NONE geolocator = Nominatim( user_agent="GCD Data Client", adapter_factory=URLLibAdapter, ssl_context=ssl_ctx ) location = geolocator.geocode({"postalcode": zip_code, "country": "US"}, exactly_one = True) in_lat = location.latitude in_lon = location.longitude return in_lat, in_lon
额外优化提示
你代码中的get_params函数定义时写了self参数,但实际调用时是作为普通函数使用,没有绑定类实例,建议删掉这个多余的self参数避免后续出现调用错误。另外公共Nominatim接口有严格的请求频率限制,生产环境建议自建Nominatim实例或使用商用地理编码服务,避免被限流。
内容的提问来源于stack exchange,提问作者Zach Rieck
相关产品推荐
相关产品推荐

