Requests请求旧SSL站点遇ssl.SSLEOFError及自定义适配器报错求助
Hey there, let's break down your problems step by step and fix them one by one:
1. Why verify=False didn't fix the SSLEOFError
The SSLEOFError occurs during the SSL handshake before certificate verification even starts. The verify=False parameter only skips checking if the server's certificate is trusted—it can't resolve handshake failures caused by incompatible protocol versions or cipher suites.
2. Fixing the SSL Handshake & Adapter Error
Your custom adapter threw an AttributeError because older versions of Requests (like your 2.8.1) use _init_poolmanager (with leading underscores) instead of init_poolmanager. Let's fix that and address the SSL compatibility issues:
Solution 1: Combine Custom Cipher Suites + Forced TLS Version
Old servers often rely on outdated TLS protocols (like TLS 1.0) and legacy cipher suites. Here's a modified adapter that fixes the method name issue and adds compatible SSL settings:
import requests import ssl from requests.adapters import HTTPAdapter from requests.packages.urllib3.util.ssl_ import create_urllib3_context # Your legacy cipher suite string CIPHERS = ( 'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:' 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:!aNULL:' '!eNULL:!MD5' ) class LegacySSLAdapter(HTTPAdapter): def _init_poolmanager(self, *args, **kwargs): # Create SSL context with custom ciphers and force TLS 1.0 (common for old servers) context = create_urllib3_context(ciphers=CIPHERS) context.protocol = ssl.PROTOCOL_TLSv1 kwargs['ssl_context'] = context return super(LegacySSLAdapter, self)._init_poolmanager(*args, **kwargs) # Initialize session and mount the adapter url = 'https://www.bestseller.com/webseller/psp.show_picture?picturesId=2367737&thumb=false' session = requests.Session() # Mount the adapter to the target domain (not full URL) for broader coverage session.mount('https://www.bestseller.com/', LegacySSLAdapter()) # Send request with verify=False to skip certificate trust check response = session.get(url, verify=False)
Solution 2: Force SSLv3 (If TLS 1.0 Still Fails)
If the server is extremely outdated, you might need to force SSLv3 (note: this is insecure, only use for trusted servers):
Modify the context line in the adapter to:
context = ssl.SSLContext(ssl.PROTOCOL_SSLv3) context.set_ciphers(CIPHERS)
3. Additional Recommendations
- Upgrade Requests (Strongly Recommended): Your Requests version (2.8.1) is very old. Upgrading to a newer release (e.g., 2.x latest or 3.x) will simplify SSL handling and eliminate issues with outdated method names. Run:
pip install --upgrade requests - Resolve OpenSSL Version Conflict: You have two different OpenSSL versions loaded (1.0.2n from Python's
sslmodule, 1.1.0g from cryptography). This can cause unpredictable behavior. Try ensuring your Python environment uses a single, consistent OpenSSL version. - Security Note: Using outdated protocols/ciphers exposes you to vulnerabilities. Only use these fixes for servers you absolutely trust and can't upgrade.
内容的提问来源于stack exchange,提问作者physicalattraction

