Vault通过TLS认证时出现CERTIFICATE_VERIFY_ERROR问题求助
Hey there! Let's break down why your Vault CLI works but your Python HVAC script is throwing that requests.exceptions.SSLError – it all comes down to how each tool handles SSL certificate verification.
Why the Discrepancy?
The Vault CLI automatically picks up your self-signed CA certificate if you've configured it (either via the VAULT_CACERT environment variable or in your ~/.vault.d/config.hcl file with ca_cert = "/path/to/ca.crt"). But the HVAC library, which uses the requests library under the hood, doesn't inherit these settings by default. That's why the server logs show tls: unknown certificate authority – your script isn't telling Vault to trust your self-signed CA.
Step-by-Step Fix
Here's how to get your HVAC script working properly:
Locate your self-signed CA certificate
Make sure you have the path to the CA certificate file you used to sign your client certs (e.g.,/home/your-user/ca.crt).Configure HVAC to trust the CA
You have two straightforward ways to do this:Option 1: Explicitly specify the CA path in the HVAC client
Pass the
verifyparameter with your CA certificate path when initializing the client:import hvac # Replace these paths with your actual file locations client = hvac.Client( url="https://your-vault-ip:8200", cert=("/path/to/client-cert.pem", "/path/to/client-key.pem"), verify="/path/to/your-ca.crt" ) # Test the authentication and secret read client.auth.cert.login() secret = client.secrets.kv.v2.read_secret_version(path="test-secret") print(secret)Option 2: Set the
REQUESTS_CA_BUNDLEenvironment variableIf you want all
requests-based tools (including HVAC) to trust your CA, set this environment variable before initializing the client:import os import hvac # Set the environment variable to your CA cert path os.environ["REQUESTS_CA_BUNDLE"] = "/path/to/your-ca.crt" client = hvac.Client( url="https://your-vault-ip:8200", cert=("/path/to/client-cert.pem", "/path/to/client-key.pem") ) # Proceed with auth and secret read client.auth.cert.login() secret = client.secrets.kv.v2.read_secret_version(path="test-secret") print(secret)
Important Note
Avoid setting verify=False unless you're in a strictly testing environment – this disables SSL certificate verification entirely, which is a major security risk. Always use the CA certificate path for production setups.
内容的提问来源于stack exchange,提问作者Alexander Nekrasov

