You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

macOS 10.13.4下升级TLS 1.0至1.2以解决Python包安装失败问题

Fixing TLS 1.0 to TLS 1.2 Upgrade for Python 2.7 on macOS 10.13.4

Hey there, let's tackle this TLS version issue head-on. First off, note that macOS's system-provided LibreSSL can't be upgraded directly—it's tied to the OS version, which is why your previous attempts to update it didn't work. Your setup (macOS 10.13.4, Python 2.7.13, LibreSSL 2.2.7) is hitting limitations because the system's default LibreSSL doesn't fully support TLS 1.2 for older Python versions, especially with that manual OpenSSL link you set up last year causing conflicts. Here are three reliable solutions:

This avoids messing with your system's default Python/LibreSSL and gives you a clean setup linked to a modern OpenSSL:

  • First, if you don't have Homebrew installed, run the official installation script:
    /usr/bin/ruby -e "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/master/install)"
    
  • Install Python 2.7 with Homebrew, which automatically links to a supported OpenSSL version:
    brew install python@2
    
  • Ensure Homebrew's Python takes priority over the system version by checking your PATH—run echo $PATH and make sure /usr/local/bin comes before /usr/bin. If not, add this line to your ~/.bash_profile or ~/.zshrc:
    export PATH="/usr/local/bin:$PATH"
    
  • Close and reopen your terminal, then verify the TLS version:
    python -c "import urllib2; import json; print(json.loads(urllib2.urlopen('https://www.howsmyssl.com/a/check').read())['tls_version'])"
    
    You should now see TLS 1.2.

If you want to keep your current Python 2.7.13, you can re-link it to a modern OpenSSL:

  • Install up-to-date OpenSSL via Homebrew:
    brew install openssl
    
  • Find your Python executable path (e.g., /usr/local/bin/python if you installed it manually, not the system /usr/bin/python). Check its current SSL links with:
    otool -L /path/to/your/python
    
  • Replace the old LibreSSL links with Homebrew's OpenSSL using install_name_tool (update paths to match your setup):
    install_name_tool -change /usr/lib/libssl.0.9.8.dylib /usr/local/opt/openssl/lib/libssl.dylib /path/to/your/python
    install_name_tool -change /usr/lib/libcrypto.0.9.8.dylib /usr/local/opt/openssl/lib/libcrypto.dylib /path/to/your/python
    
  • Verify the change by checking the OpenSSL version in Python:
    python -c "import ssl; print(ssl.OPENSSL_VERSION)"
    
    It should show an OpenSSL 1.x version, not LibreSSL. Then re-check your TLS version as before.

Option 3: Temporary Workaround (Emergency Fix Only)

If you just need to install a package quickly without full system changes, force TLS 1.2 in your Python context:

  • When using pip, set this environment variable first:
    export SSL_CIPHERS='DEFAULT@SECLEVEL=1'
    pip install your-package-name
    
  • Or in custom Python code, explicitly enable TLS 1.2:
    import ssl
    import urllib2
    
    ctx = ssl.create_default_context()
    ctx.options |= ssl.OP_NO_TLSv1 | ssl.OP_NO_TLSv1_1
    response = urllib2.urlopen('https://your-target-url.com', context=ctx)
    
    Note: This is a band-aid, not a permanent fix.

Key Notes

  • Never modify the system's default Python (/usr/bin/python) or LibreSSL—this can break core macOS functionality.
  • If you previously set DYLD_LIBRARY_PATH or LD_LIBRARY_PATH for OpenSSL, update it to point to Homebrew's version:
    export DYLD_LIBRARY_PATH="/usr/local/opt/openssl/lib:$DYLD_LIBRARY_PATH"
    

内容的提问来源于stack exchange,提问作者Lucas03

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:01:05