Ошибка "[SSL: CA_MD_TOO_WEAK] ca md too weak (_ssl.c:3862)')" при использовании requests с сертификатом
Есть у меня скрипт для работы, который по сертификату ходит на корпоративный сайт:
PEM_FILE_NAME = str(DIR / 'ipetrash.pem')
headers = {
'User-Agent': USER_AGENT,
}
rs = requests.post(URL, data=data, headers=headers, cert=PEM_FILE_NAME, verify=False)
Но он перестал работать. Подозреваю, что причина в обновлении ssl в python3.10
Как его починить?
Ошибка:
Traceback (most recent call last):
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\urllib3\connectionpool.py", line 699, in urlopen
httplib_response = self._make_request(
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\urllib3\connectionpool.py", line 382, in _make_request
self._validate_conn(conn)
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\urllib3\connectionpool.py", line 1010, in _validate_conn
conn.connect()
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\urllib3\connection.py", line 416, in connect
self.sock = ssl_wrap_socket(
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\urllib3\util\ssl_.py", line 418, in ssl_wrap_socket
context.load_cert_chain(certfile, keyfile)
ssl.SSLError: [SSL: CA_MD_TOO_WEAK] ca md too weak (_ssl.c:3862)
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\requests\adapters.py", line 439, in send
resp = conn.urlopen(
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\urllib3\connectionpool.py", line 755, in urlopen
retries = retries.increment(
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\urllib3\util\retry.py", line 574, in increment
raise MaxRetryError(_pool, url, error or ResponseError(cause))
urllib3.exceptions.MaxRetryError: HTTPSConnectionPool(host='jira.compassplus.ru', port=443): Max retries exceeded with url: /pa-reports/ (Caused by SSLError(SSLError(398, '[SSL: CA_MD_TOO_WEAK] ca md too weak (_ssl.c:3862)')))
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "C:\Users\ipetrash\PycharmProjects\SimplePyScripts\current_job_report\get_user_and_deviation_hours.py", line 169, in <module>
name, deviation_hours = get_user_and_deviation_hours()
File "C:\Users\ipetrash\PycharmProjects\SimplePyScripts\current_job_report\get_user_and_deviation_hours.py", line 159, in get_user_and_deviation_hours
content = get_report_context()
File "C:\Users\ipetrash\PycharmProjects\SimplePyScripts\current_job_report\get_user_and_deviation_hours.py", line 74, in get_report_context
return _send_data(data)
File "C:\Users\ipetrash\PycharmProjects\SimplePyScripts\current_job_report\get_user_and_deviation_hours.py", line 58, in _send_data
rs = session.post(URL, data=data)
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\requests\sessions.py", line 590, in post
return self.request('POST', url, data=data, json=json, **kwargs)
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\requests\sessions.py", line 542, in request
resp = self.send(prep, **send_kwargs)
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\requests\sessions.py", line 655, in send
r = adapter.send(request, **kwargs)
File "C:\Users\ipetrash\AppData\Local\Programs\Python\Python310\lib\site-packages\requests\adapters.py", line 514, in send
raise SSLError(e, request=request)
requests.exceptions.SSLError: HTTPSConnectionPool(host='jira.compassplus.ru', port=443): Max retries exceeded with url: /pa-reports/ (Caused by SSLError(SSLError(398, '[SSL: CA_MD_TOO_WEAK] ca md too weak (_ssl.c:3862)')))
Ответы (1 шт):
Автор решения: gil9red
→ Ссылка
Помогло это решение через создание TLSAdapter от requests.adapters.HTTPAdapter, в котором устанавливается настройка DEFAULT@SECLEVEL=1. А эта настройка снизит уровень безопасности до того уровня, что использовался в старой версии openssl
class TLSAdapter(requests.adapters.HTTPAdapter):
def init_poolmanager(self, *args, **kwargs):
ctx = ssl.create_default_context()
ctx.set_ciphers('DEFAULT@SECLEVEL=1')
kwargs['ssl_context'] = ctx
return super(TLSAdapter, self).init_poolmanager(*args, **kwargs)
URL = 'https://jira.compassplus.ru/pa-reports/'
USER_AGENT = 'Mozilla/5.0 (Windows NT 6.1; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0'
PEM_FILE_NAME = str(DIR / 'ipetrash.pem')
session = requests.session()
session.cert = PEM_FILE_NAME
session.mount('https://', TLSAdapter())
session.headers['User-Agent'] = USER_AGENT
rs = session.post(URL, data=data)