Alex Leko
All content on this blog was fully or partially created using local AI (Apple MLX).

Ignoring SSL certificate errors in Python requests

  • python
  • ssl
  • security

This error means Python's requests library cannot verify the server's SSL certificate. It can happen with self-signed certificates or an outdated certificate store.

Security warning: Disabling SSL verification leaves your connection vulnerable to MITM attacks. Use this only for testing, or when you trust the source and cannot fix the certificate issue.

Option 1: Disable verification

With requests, set verify=False.

import requests

try:
    response = requests.get(
        "https://example.com",
        verify=False,  # Disables SSL verification
        timeout=10
    )
    response.raise_for_status()
except requests.exceptions.SSLError as e:
    print(f"SSL Error occurred: {e}")
except Exception as e:
    print(f"Other error: {e}")

Suppress the InsecureRequestWarning: Using verify=False logs a warning. To suppress it:

import urllib3
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)

import requests

response = requests.get(url, verify=False)

Option 2: Fix the certificate

Provide the path to the Certificate Authority (CA) bundle or update your system's certificates.

  1. Update certifi (Python's certificate store):

    pip install --upgrade certifi
    
  2. If you have the certificate file, point requests to it:

    response = requests.get(url, verify="/path/to/cert.pem")
    

Option 3: Use urllib3 directly

If you are not using requests and calling urllib3 directly:

import urllib3

http = urllib3.PoolManager(
    cert_reqs='CERT_NONE',  # Ignores SSL verification
    assert_hostname=False
)

response = http.request('GET', 'https://example.com')

Option 4: Set an environment variable

You can set an environment variable to disable verification for the entire script. Avoid this in production:

import os
os.environ['REQUESTS_CA_BUNDLE'] = ''

# Or for urllib3
import urllib3
urllib3.disable_warnings()

For a one-off script or local testing, you can use Option 1 and suppress the warning. In production, find out why the server's certificate is invalid and fix it rather than bypassing verification.