SSL: CERTIFICATE_VERIFY_FAILED — certificate verify failed (pip / Python)
Python cannot verify the server's TLS certificate — usually a corporate proxy re-signing traffic, or a Python install without its certificate bundle. Point Python at the right CA bundle instead of disabling verification.
Updated
The error
Could not fetch URL https://pypi.org/simple/torch/: There was a problem confirming the ssl certificate: HTTPSConnectionPool(host='pypi.org', port=443): Max retries exceeded with url: /simple/torch/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1006)'))) - skipping
The same CERTIFICATE_VERIFY_FAILED core appears in requests, urllib and every API SDK.
What it means
TLS connections are verified against a bundle of trusted certificate authorities (CAs). Python checked the certificate the server presented and could not chain it to any CA it trusts. Either the certificate really is untrusted — because a middlebox rewrote it — or Python's trust bundle is missing or stale. The server (PyPI, Hugging Face, an API) is almost never the problem.
Why it happens
Two dominant causes:
- Corporate TLS interception. Company proxies decrypt and re-encrypt HTTPS, presenting their own certificate signed by the company's private CA. Browsers trust it (IT installed the CA on the machine); Python uses its own bundle and does not.
- Python missing its certificates, classically the python.org installer on macOS, which ships a certifi bundle that must be activated once.
Rarely: a badly wrong system clock (certificates appear expired), or genuinely hostile networks.
How to fix it
1. On macOS with python.org Python, run the bundled certificate installer once.
/Applications/Python\ 3.12/Contents/MacOS/../Resources/Install\ Certificates.commandOr double-click "Install Certificates.command" in the Python folder in Applications. This wires Python to the certifi bundle and ends the errors.
2. On corporate networks, obtain the company root CA and point Python at it. Ask IT for the root certificate (a .pem/.crt file), then:
export SSL_CERT_FILE=/path/to/company-root-ca.pem
export REQUESTS_CA_BUNDLE=/path/to/company-root-ca.pem
pip config set global.cert /path/to/company-root-ca.pemThe two variables cover Python libraries; the pip config covers pip itself. This is the correct fix: verification stays on, trusting exactly one extra CA.
3. Refresh certifi.
python -m pip install --upgrade certifiCheap, and fixes stale-bundle cases.
4. Check the system clock. A clock years off makes every certificate invalid. Sync time and retry before deeper surgery.
5. --trusted-host is the emergency hatch, not the fix.
pip install --trusted-host pypi.org --trusted-host files.pythonhosted.org somepackageIt disables verification for those hosts — acceptable to unblock one install on a network you trust, unacceptable as permanent configuration. Never replicate the equivalent (verify=False) inside application code that handles real data.
How to prevent it
On corporate machines, set the CA bundle variables in your shell profile once, documented for the team. Include them in Dockerfiles and CI configuration for builds behind the proxy. Treat any advice to switch verification off as a request to type your credentials onto an unverified line.
Related errors
- APIConnectionError (OpenAI/Anthropic) — how this surfaces inside LLM SDKs
- We couldn't connect to huggingface.co
- Could not find a version that satisfies the requirement — SSL failures masquerading as missing packages