Last modified: Oct 01, 2026
Fix pip install SSL Certificate Error
The pip install SSL certificate error is one of the most common problems Python developers face. It usually appears when pip tries to download a package from PyPI over HTTPS.
The connection fails because Python cannot verify the SSL certificate of the server. This can stop your work completely.
In this guide, you will learn why this error happens and how to fix it step by step. The solutions work on Windows, macOS, and Linux.
What Causes the pip SSL Certificate Error?
Pip uses SSL to talk to the Python Package Index (PyPI) securely. When the SSL handshake fails, pip throws an error.
Here are the most common causes:
1. Outdated certificates. Your system may have old or missing root certificates.
2. A proxy or firewall. Corporate networks often intercept HTTPS traffic. This breaks certificate validation.
3. Missing certifi package. Pip relies on the certifi package for trusted certificates.
4. Wrong system time. An incorrect clock can make valid certificates look expired.
5. Old pip or Python version. Older versions may not support modern TLS protocols.
What the Error Looks Like
You will see a message similar to this when you run a pip command:
$ pip install requests
Could not fetch URL https://pypi.org/simple/requests/:
There was a problem confirming the ssl certificate:
[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed:
unable to get local issuer certificate (_ssl.c:1006)
The key phrase is CERTIFICATE_VERIFY_FAILED. That tells you the problem is SSL-related, not a missing package.
Solution 1: Upgrade pip and Python
Before anything else, update pip. Newer versions handle certificates better.
# Upgrade pip to the latest version
python -m pip install --upgrade pip
If pip itself cannot connect, use the trusted host flag for this one command:
# Temporary fix to upgrade pip
python -m pip install --upgrade pip --trusted-host pypi.org --trusted-host files.pythonhosted.org
After the upgrade, try your original command again. Many users find the error disappears.
Solution 2: Install or Reinstall certifi
The certifi package provides a curated list of trusted root certificates. If it is missing or broken, pip fails.
# Reinstall certifi to refresh certificates
pip install --upgrade --force-reinstall certifi
You can check where certifi stores its bundle:
# Print the path to the certifi certificate bundle
import certifi
print(certifi.where())
# Example output
/usr/local/lib/python3.11/site-packages/certifi/cacert.pem
If that file exists, your certificates are in place. If not, reinstall certifi as shown above.
Solution 3: Use the Trusted Host Option
The --trusted-host flag tells pip to skip certificate verification for specific hosts. This is a quick workaround.
# Install a package while trusting PyPI hosts
pip install requests --trusted-host pypi.org --trusted-host files.pythonhosted.org
Warning: This lowers security. Only use it when you trust your network. Do not use it on public Wi-Fi.
To make it permanent, add the hosts to your pip configuration file. On Linux and macOS, edit ~/.pip/pip.conf. On Windows, edit %APPDATA%\pip\pip.ini.
# Add these lines to your pip config file
[global]
trusted-host = pypi.org
files.pythonhosted.org
Solution 4: Fix Your System Certificates
Sometimes the problem is your operating system, not pip. Install the correct root certificates for your platform.
On macOS: Run the certificate installer that ships with Python.
# Run the macOS certificate installer
/Applications/Python\ 3.11/Install\ Certificates.command
On Windows: Update your system with Windows Update. It refreshes root certificates automatically.
On Linux: Install the CA certificates package for your distribution.
# Debian or Ubuntu
sudo apt-get install ca-certificates
# Red Hat or CentOS
sudo yum install ca-certificates
Solution 5: Check Your System Time
An incorrect system clock is a hidden cause. If your date or time is wrong, valid certificates appear expired.
Check the date on your machine:
# Show current system date and time
date
If the date is wrong, sync it with a time server. On most systems, enabling automatic time sync fixes this. This is a simple fix that many people overlook.
Solution 6: Handle Proxy and Firewall Issues
Corporate proxies often replace SSL certificates. This breaks pip because the proxy certificate is not trusted.
First, check if a proxy is set:
# Show environment proxy variables
echo $HTTP_PROXY
echo $HTTPS_PROXY
If you are behind a proxy, ask your IT team for the correct certificate. Then point pip to it:
# Tell pip to use a specific CA bundle
pip install requests --cert /path/to/company-ca-bundle.pem
You can also set the REQUESTS_CA_BUNDLE environment variable. This helps pip and other Python tools find the right certificate.
# Set the CA bundle path for the session
export REQUESTS_CA_BUNDLE=/path/to/company-ca-bundle.pem
Solution 7: Use a Different Index or Mirror
Sometimes the PyPI server itself has issues. Try a trusted mirror instead.
# Install from a mirror index
pip install requests --index-url https://pypi.org/simple/
If you are in a region with slow access to PyPI, a local mirror can also solve SSL timeouts.
How to Prevent the Error in the Future
Keep your tools updated. Run pip install --upgrade pip regularly.
Keep your operating system patched. System updates refresh root certificates.
Use a virtual environment for each project. This keeps dependencies clean and avoids conflicts.
Avoid the --trusted-host flag unless you must. It is a workaround, not a real fix.
If you work behind a proxy, save the correct certificate path in your pip config. This saves time later.
Quick Troubleshooting Checklist
Follow these steps in order when the error appears:
1. Upgrade pip and Python.
2. Reinstall the certifi package.
3. Check your system date and time.
4. Update system root certificates.
5. Use --trusted-host as a temporary test.
6. Check proxy and firewall settings.
7. Try a different package index.
This order moves from safe fixes to riskier workarounds. Start at the top and stop when the error goes away.
Conclusion
The pip install SSL certificate error is frustrating, but it is fixable. The cause is almost always a certificate, a clock, or a proxy issue.
Start with the simple fixes. Upgrade pip. Reinstall certifi. Check your system time. These steps solve most cases.
If you are behind a corporate proxy, get the right certificate from your IT team. Then point pip to it with the --cert option.
Use --trusted-host only as a last resort. It works, but it lowers your security.
With the steps in this guide, you can get back to installing packages in minutes. Keep your tools updated, and this error will rarely return.