Google API密钥本地正常服务器报错SSLHandshakeError求助
Hey there, let's work through this SSL certificate verification failure you're hitting after deploying your Google API integration to production. Local tests work fine, so the issue is almost certainly related to your server's SSL certificate trust setup—here are the most effective fixes to try:
1. Refresh System CA Certificates
Python 2.7's SSL module relies on your Ubuntu server's root certificate store. If this store is outdated or incomplete, it won't recognize Google's SSL certificate. Run these commands to update it:
sudo apt-get update && sudo apt-get install --reinstall ca-certificates sudo update-ca-certificates
This ensures your server has the latest trusted root certificates, including those used by Google APIs.
2. Force Python to Use the Correct Certificate Path
Sometimes Python can't automatically find the system certificate bundle. You can explicitly tell your API requests to use it in two ways:
Option A: Set in Code
When making requests to the Google API (using requests or similar libraries), add the verify parameter pointing to Ubuntu's default certificate file:
import requests response = requests.get("https://your-google-api-endpoint", verify="/etc/ssl/certs/ca-certificates.crt")
Option B: Set Environment Variable
Add this environment variable to ensure all Python requests use the correct certificate bundle, then restart your services:
export REQUESTS_CA_BUNDLE="/etc/ssl/certs/ca-certificates.crt" # Restart Unicorn and Nginx after setting this sudo service unicorn restart sudo service nginx restart
If you're using a Unicorn config file, you can add the environment variable directly there (e.g., in config/unicorn.rb) to make it persistent across restarts:
ENV['REQUESTS_CA_BUNDLE'] = '/etc/ssl/certs/ca-certificates.crt'
3. Verify Unicorn's Environment Context
Unicorn sometimes runs with a limited environment that doesn't include system-wide SSL settings. Double-check that your Unicorn process has access to the REQUESTS_CA_BUNDLE variable by running:
ps aux | grep unicorn
Look for the environment variables associated with the Unicorn process—if REQUESTS_CA_BUNDLE isn't listed, you'll need to add it to your Unicorn startup script or config as mentioned above.
4. Test the SSL Connection Directly
To rule out any network or certificate chain issues, run this OpenSSL command on your server to connect to Google's API endpoint:
openssl s_client -connect googleapis.com:443
Look for the "Verify return code" line at the end—if it says 0 (ok), the certificate chain is working correctly. If not, you may need to manually add missing intermediate certificates to your system's /usr/local/share/ca-certificates/ directory and run sudo update-ca-certificates again.
Quick Note on Python 2.7
Just a heads up: Python 2.7 is no longer supported, which means it won't receive security updates for SSL vulnerabilities. If you can plan an upgrade to Python 3.x in the near future, it'll eliminate many of these legacy SSL-related headaches long-term.
内容的提问来源于stack exchange,提问作者vinay kumar

