You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Vault通过TLS认证时出现CERTIFICATE_VERIFY_ERROR问题求助

Fixing HVAC SSL Error with Self-Signed Vault CA

Hey there! Let's break down why your Vault CLI works but your Python HVAC script is throwing that requests.exceptions.SSLError – it all comes down to how each tool handles SSL certificate verification.

Why the Discrepancy?

The Vault CLI automatically picks up your self-signed CA certificate if you've configured it (either via the VAULT_CACERT environment variable or in your ~/.vault.d/config.hcl file with ca_cert = "/path/to/ca.crt"). But the HVAC library, which uses the requests library under the hood, doesn't inherit these settings by default. That's why the server logs show tls: unknown certificate authority – your script isn't telling Vault to trust your self-signed CA.

Step-by-Step Fix

Here's how to get your HVAC script working properly:

  1. Locate your self-signed CA certificate
    Make sure you have the path to the CA certificate file you used to sign your client certs (e.g., /home/your-user/ca.crt).

  2. Configure HVAC to trust the CA
    You have two straightforward ways to do this:

    Option 1: Explicitly specify the CA path in the HVAC client

    Pass the verify parameter with your CA certificate path when initializing the client:

    import hvac
    
    # Replace these paths with your actual file locations
    client = hvac.Client(
        url="https://your-vault-ip:8200",
        cert=("/path/to/client-cert.pem", "/path/to/client-key.pem"),
        verify="/path/to/your-ca.crt"
    )
    
    # Test the authentication and secret read
    client.auth.cert.login()
    secret = client.secrets.kv.v2.read_secret_version(path="test-secret")
    print(secret)
    

    Option 2: Set the REQUESTS_CA_BUNDLE environment variable

    If you want all requests-based tools (including HVAC) to trust your CA, set this environment variable before initializing the client:

    import os
    import hvac
    
    # Set the environment variable to your CA cert path
    os.environ["REQUESTS_CA_BUNDLE"] = "/path/to/your-ca.crt"
    
    client = hvac.Client(
        url="https://your-vault-ip:8200",
        cert=("/path/to/client-cert.pem", "/path/to/client-key.pem")
    )
    
    # Proceed with auth and secret read
    client.auth.cert.login()
    secret = client.secrets.kv.v2.read_secret_version(path="test-secret")
    print(secret)
    

Important Note

Avoid setting verify=False unless you're in a strictly testing environment – this disables SSL certificate verification entirely, which is a major security risk. Always use the CA certificate path for production setups.

内容的提问来源于stack exchange,提问作者Alexander Nekrasov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:29:52