macOS 10.13.4下升级TLS 1.0至1.2以解决Python包安装失败问题
Hey there, let's tackle this TLS version issue head-on. First off, note that macOS's system-provided LibreSSL can't be upgraded directly—it's tied to the OS version, which is why your previous attempts to update it didn't work. Your setup (macOS 10.13.4, Python 2.7.13, LibreSSL 2.2.7) is hitting limitations because the system's default LibreSSL doesn't fully support TLS 1.2 for older Python versions, especially with that manual OpenSSL link you set up last year causing conflicts. Here are three reliable solutions:
Option 1: Reinstall Python 2.7 via Homebrew (Recommended)
This avoids messing with your system's default Python/LibreSSL and gives you a clean setup linked to a modern OpenSSL:
- First, if you don't have Homebrew installed, run the official installation script:
/usr/bin/ruby -e "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/master/install)" - Install Python 2.7 with Homebrew, which automatically links to a supported OpenSSL version:
brew install python@2 - Ensure Homebrew's Python takes priority over the system version by checking your
PATH—runecho $PATHand make sure/usr/local/bincomes before/usr/bin. If not, add this line to your~/.bash_profileor~/.zshrc:export PATH="/usr/local/bin:$PATH" - Close and reopen your terminal, then verify the TLS version:
You should now see TLS 1.2.python -c "import urllib2; import json; print(json.loads(urllib2.urlopen('https://www.howsmyssl.com/a/check').read())['tls_version'])"
Option 2: Fix Existing Python's OpenSSL Link (For Non-Reinstall Preference)
If you want to keep your current Python 2.7.13, you can re-link it to a modern OpenSSL:
- Install up-to-date OpenSSL via Homebrew:
brew install openssl - Find your Python executable path (e.g.,
/usr/local/bin/pythonif you installed it manually, not the system/usr/bin/python). Check its current SSL links with:otool -L /path/to/your/python - Replace the old LibreSSL links with Homebrew's OpenSSL using
install_name_tool(update paths to match your setup):install_name_tool -change /usr/lib/libssl.0.9.8.dylib /usr/local/opt/openssl/lib/libssl.dylib /path/to/your/python install_name_tool -change /usr/lib/libcrypto.0.9.8.dylib /usr/local/opt/openssl/lib/libcrypto.dylib /path/to/your/python - Verify the change by checking the OpenSSL version in Python:
It should show an OpenSSL 1.x version, not LibreSSL. Then re-check your TLS version as before.python -c "import ssl; print(ssl.OPENSSL_VERSION)"
Option 3: Temporary Workaround (Emergency Fix Only)
If you just need to install a package quickly without full system changes, force TLS 1.2 in your Python context:
- When using
pip, set this environment variable first:export SSL_CIPHERS='DEFAULT@SECLEVEL=1' pip install your-package-name - Or in custom Python code, explicitly enable TLS 1.2:
Note: This is a band-aid, not a permanent fix.import ssl import urllib2 ctx = ssl.create_default_context() ctx.options |= ssl.OP_NO_TLSv1 | ssl.OP_NO_TLSv1_1 response = urllib2.urlopen('https://your-target-url.com', context=ctx)
Key Notes
- Never modify the system's default Python (
/usr/bin/python) or LibreSSL—this can break core macOS functionality. - If you previously set
DYLD_LIBRARY_PATHorLD_LIBRARY_PATHfor OpenSSL, update it to point to Homebrew's version:export DYLD_LIBRARY_PATH="/usr/local/opt/openssl/lib:$DYLD_LIBRARY_PATH"
内容的提问来源于stack exchange,提问作者Lucas03

