Error database

SSL: CERTIFICATE_VERIFY_FAILED — certificate verify failed (pip / Python)

Python cannot verify the server's TLS certificate — usually a corporate proxy re-signing traffic, or a Python install without its certificate bundle. Point Python at the right CA bundle instead of disabling verification.

The message you saw
SSL: CERTIFICATE_VERIFY_FAILED — certificate verify failed (pip / Python)

By Updated

The error

Output
Could not fetch URL https://pypi.org/simple/torch/: There was a problem confirming the ssl certificate: HTTPSConnectionPool(host='pypi.org', port=443): Max retries exceeded with url: /simple/torch/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006)'))) - skipping

The same CERTIFICATE_VERIFY_FAILED core appears in requests, urllib and every API SDK.

What it means

TLS connections are verified against a bundle of trusted certificate authorities (CAs). Python checked the certificate the server presented and could not chain it to any CA it trusts. Either the certificate really is untrusted — because a middlebox rewrote it — or Python's trust bundle is missing or stale. The server (PyPI, Hugging Face, an API) is almost never the problem.

Why it happens

Two dominant causes:

  • Corporate TLS interception. Company proxies decrypt and re-encrypt HTTPS, presenting their own certificate signed by the company's private CA. Browsers trust it (IT installed the CA on the machine); Python uses its own bundle and does not.
  • Python missing its certificates, classically the python.org installer on macOS, which ships a certifi bundle that must be activated once.

Rarely: a badly wrong system clock (certificates appear expired), or genuinely hostile networks.

How to fix it

1. On macOS with python.org Python, run the bundled certificate installer once.

bash
/Applications/Python\ 3.12/Contents/MacOS/../Resources/Install\ Certificates.command

Or double-click "Install Certificates.command" in the Python folder in Applications. This wires Python to the certifi bundle and ends the errors.

2. On corporate networks, obtain the company root CA and point Python at it. Ask IT for the root certificate (a .pem/.crt file), then:

bash
export SSL_CERT_FILE=/path/to/company-root-ca.pem
export REQUESTS_CA_BUNDLE=/path/to/company-root-ca.pem
pip config set global.cert /path/to/company-root-ca.pem

The two variables cover Python libraries; the pip config covers pip itself. This is the correct fix: verification stays on, trusting exactly one extra CA.

3. Refresh certifi.

bash
python -m pip install --upgrade certifi

Cheap, and fixes stale-bundle cases.

4. Check the system clock. A clock years off makes every certificate invalid. Sync time and retry before deeper surgery.

5. --trusted-host is the emergency hatch, not the fix.

bash
pip install --trusted-host pypi.org --trusted-host files.pythonhosted.org somepackage

It disables verification for those hosts — acceptable to unblock one install on a network you trust, unacceptable as permanent configuration. Never replicate the equivalent (verify=False) inside application code that handles real data.

How to prevent it

On corporate machines, set the CA bundle variables in your shell profile once, documented for the team. Include them in Dockerfiles and CI configuration for builds behind the proxy. Treat any advice to switch verification off as a request to type your credentials onto an unverified line.