尝试打开Nav Canada网站时SSL:CERTIFICATE_VERIFY_FAILED

时间:2017-11-12 02:43:55

标签: python html css ssl python-requests

我创建了一个脚本,从以下地址的Nav Canada网站上删除最新的航空气象数据;

https://flightplanning.navcanada.ca/cgi-bin/lab/lab.cgi?Langue=anglais&NoSession=NS_Inconnu&TypeBrief=L&Version=T&AerodromeId=CYOW&cw_metar=dcd_metar&fw_gfaCld=on&fw_gfaIcg=on&rwt_uprWindsFD180=on

我使用这些数据来计算一些变量并使用raspberry pi在我自己的Web服务器上显示它。经过几个月没有麻烦,我几天前遇到了这个错误。我尝试将链接切换到另一个网站,看看它是否是请求模块的错误,但其他网站工作正常。是否有可能以某种方式禁止以这种方式访问​​他们的网站?我仍然可以通过浏览器访问它。或者是他没有想到的另一个潜在问题?这是堆栈跟踪。

Traceback (most recent call last):
  File "C:\Program Files\Python36\lib\urllib\request.py", line 1318, in do_open
    encode_chunked=req.has_header('Transfer-encoding'))
  File "C:\Program Files\Python36\lib\http\client.py", line 1239, in request
    self._send_request(method, url, body, headers, encode_chunked)
  File "C:\Program Files\Python36\lib\http\client.py", line 1285, in _send_request
    self.endheaders(body, encode_chunked=encode_chunked)
  File "C:\Program Files\Python36\lib\http\client.py", line 1234, in endheaders
    self._send_output(message_body, encode_chunked=encode_chunked)
  File "C:\Program Files\Python36\lib\http\client.py", line 1026, in _send_output
    self.send(msg)
  File "C:\Program Files\Python36\lib\http\client.py", line 964, in send
    self.connect()
  File "C:\Program Files\Python36\lib\http\client.py", line 1400, in connect
    server_hostname=server_hostname)
  File "C:\Program Files\Python36\lib\ssl.py", line 401, in wrap_socket
    _context=self, _session=session)
  File "C:\Program Files\Python36\lib\ssl.py", line 808, in __init__
    self.do_handshake()
  File "C:\Program Files\Python36\lib\ssl.py", line 1061, in do_handshake
    self._sslobj.do_handshake()
  File "C:\Program Files\Python36\lib\ssl.py", line 683, in do_handshake
    self._sslobj.do_handshake()
ssl.SSLError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:749)

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "C:/Users/Philip Naida/Google Drive/Projects/WeatherDataCollector/WeatherDataCollector v_5.0/WeatherDataCollector.py", line 15, in <module>
    source = urllib.request.urlopen('https://flightplanning.navcanada.ca/cgi-bin/CreePage.pl?Langue=anglais&NoSession=NS_Inconnu&Page=forecast-observation&TypeDoc=html').read()
  File "C:\Program Files\Python36\lib\urllib\request.py", line 223, in urlopen
    return opener.open(url, data, timeout)
  File "C:\Program Files\Python36\lib\urllib\request.py", line 526, in open
    response = self._open(req, data)
  File "C:\Program Files\Python36\lib\urllib\request.py", line 544, in _open
    '_open', req)
  File "C:\Program Files\Python36\lib\urllib\request.py", line 504, in _call_chain
    result = func(*args)
  File "C:\Program Files\Python36\lib\urllib\request.py", line 1361, in https_open
    context=self._context, check_hostname=self._check_hostname)
  File "C:\Program Files\Python36\lib\urllib\request.py", line 1320, in do_open
    raise URLError(err)
urllib.error.URLError: <urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:749)>

如果可以的话,你们中的任何人都可以尝试使用urllib访问这个网页吗?看看会发生什么?任何帮助将不胜感激我希望我的服务器重新上线。

由于

2 个答案:

答案 0 :(得分:0)

查看此网站的report from SSLLabs,您会看到许多其他警告:

  

此服务器的证书链不完整。

如果您查看更多详细信息,您将看到服务器仅提供叶证书,但未能提供构建信任链到本地根证书所需的中间证书。

桌面浏览器通常(但并非总是)通过尝试从其他地方自动获取丢失的证书来解决此类配置错误的服务器。但是其他应用程序(如Python,Perl,Java ...应用程序)只是失败了,因为如果没有缺少中间证书就无法正确验证证书。

要解决此服务器,您需要自己提供中间证书。这可以通过例如以下请求来完成:

import requests
response = request.get('https://flightplanning.navcanada.ca', verify='mycerts.pem')

mycerts.pem包含所有缺少的中间证书和您信任的根证书。您可以在https://pastebin.com/zi5BN2Vt

找到修复此特定服务器连接的文件

答案 1 :(得分:-1)

该网站使用TLS 1.0(过时的协议),RSA(过时的密钥交换)和AES_128_CBC与HMAC-SHA1(过时的密码)。如果您想继续使用它,我建议使用流行的requests包。它允许您在发送请求时关闭服务器验证。

import requests

url = ('https://flightplanning.navcanada.ca/cgi-bin/lab/lab.cgi?Langue=anglais' 
       '&NoSession=NS_Inconnu&TypeBrief=L&Version=T&AerodromeId=CYOW&cw_metar='
       'dcd_metar&fw_gfaCld=on&fw_gfaIcg=on&rwt_uprWindsFD180=on')

res = request.get(url, verify=False)

# you will get the following warning
InsecureRequestWarning: Unverified HTTPS request is being made. Adding certificate 
verification is strongly advised. See: https://urllib3.readthedocs.io
/en/latest/advanced-usage.html#ssl-warnings    InsecureRequestWarning)

res
# returns:
<Response [200]>