Ignoring SSL certificate errors in Python requests
This error means Python's requests library cannot verify the server's SSL certificate. It can happen with self-signed certificates or an outdated certificate store.
Security warning: Disabling SSL verification leaves your connection vulnerable to MITM attacks. Use this only for testing, or when you trust the source and cannot fix the certificate issue.
Option 1: Disable verification
With requests, set verify=False.
import requests
try:
response = requests.get(
"https://example.com",
verify=False, # Disables SSL verification
timeout=10
)
response.raise_for_status()
except requests.exceptions.SSLError as e:
print(f"SSL Error occurred: {e}")
except Exception as e:
print(f"Other error: {e}")
Suppress the InsecureRequestWarning:
Using verify=False logs a warning. To suppress it:
import urllib3
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
import requests
response = requests.get(url, verify=False)
Option 2: Fix the certificate
Provide the path to the Certificate Authority (CA) bundle or update your system's certificates.
Update
certifi(Python's certificate store):pip install --upgrade certifiIf you have the certificate file, point
requeststo it:response = requests.get(url, verify="/path/to/cert.pem")
Option 3: Use urllib3 directly
If you are not using requests and calling urllib3 directly:
import urllib3
http = urllib3.PoolManager(
cert_reqs='CERT_NONE', # Ignores SSL verification
assert_hostname=False
)
response = http.request('GET', 'https://example.com')
Option 4: Set an environment variable
You can set an environment variable to disable verification for the entire script. Avoid this in production:
import os
os.environ['REQUESTS_CA_BUNDLE'] = ''
# Or for urllib3
import urllib3
urllib3.disable_warnings()
For a one-off script or local testing, you can use Option 1 and suppress the warning. In production, find out why the server's certificate is invalid and fix it rather than bypassing verification.