使用Python-requests搭配Cntlm企业代理时遭遇407认证失败求助
Hey there! I see you've got Cntlm set up and working for tools like wget, curl, and pip, but your requests code is throwing a 407 error. Let's walk through the common fixes for this issue.
Why This Happens
Even though your system-level proxy is configured correctly, requests might not be picking up the proxy settings automatically, or there could be a mismatch in how it handles proxy tunneling compared to other tools. Cntlm acts as a local proxy that handles authentication with your enterprise proxy, so we need to make sure requests is pointing directly to Cntlm.
Solutions to Try
1. Explicitly Set Proxies in Your Requests Session
The most straightforward fix is to tell requests exactly where your Cntlm proxy is running (default is 127.0.0.1:3128). Update your code like this:
import requests url = 'https://apple.com' session = requests.session() # Configure proxies to point to Cntlm proxies = { 'http': 'http://127.0.0.1:3128', 'https': 'http://127.0.0.1:3128' } r = session.get(url, proxies=proxies) print(r.text)
Note: We use http:// for both HTTP and HTTPS proxies here because Cntlm handles the HTTPS tunneling for you.
2. Ensure Python Picks Up Your System Proxy Environment Variables
requests normally reads HTTP_PROXY and HTTPS_PROXY environment variables, but sometimes these aren't passed to your Python process.
First, verify the variables exist in your shell:
echo $HTTP_PROXY echo $HTTPS_PROXY
If they show http://127.0.0.1:3128, but your Python code isn't using them, you can manually set them in your script:
import os import requests # Set environment variables for proxies os.environ['HTTP_PROXY'] = 'http://127.0.0.1:3128' os.environ['HTTPS_PROXY'] = 'http://127.0.0.1:3128' url = 'https://apple.com' session = requests.session() r = session.get(url) print(r.text)
3. Verify Your Cntlm Configuration
Double-check your cntlm.conf file to make sure:
- The
Listendirective is set to127.0.0.1:3128(or0.0.0.0:3128to allow all local connections) - You've generated the correct NTLM hashes using
cntlm -Hand added them to the config (replace plaintext passwords with these hashes) - The
Username,Domain, and other authentication details are correct
After making changes, restart the Cntlm service:
sudo systemctl restart cntlm # Or for older systems: sudo service cntlm restart
4. Disable Automatic Proxy Detection
Sometimes requests tries to auto-detect proxies, which can conflict with Cntlm. Disable this feature and manually set the proxy:
import requests url = 'https://apple.com' session = requests.session() # Disable automatic proxy detection session.trust_env = False # Manually set proxies proxies = { 'http': 'http://127.0.0.1:3128', 'https': 'http://127.0.0.1:3128' } r = session.get(url, proxies=proxies) print(r.text)
Final Notes
In most cases, explicitly setting the proxies in your requests session (solution 1) will resolve the 407 error. If not, verifying your Cntlm config and ensuring environment variables are correctly passed should do the trick.
内容的提问来源于stack exchange,提问作者Andrew

