{"record":{"id":"05dc1acea9c2e012","repo":"pypa/pip","slug":"ssl-missing","errorCode":"ssl-missing","errorMessage":"Failed to establish a secure connection for {url}","messagePattern":"Failed to establish a secure connection for (.+?)","errorType":"exception","errorClass":"SSLMissingError","httpStatus":null,"severity":"critical","filePath":"src/pip/_internal/network/session.py","lineNumber":548,"sourceCode":"\n    def request(self, method: str, url: str, *args: Any, **kwargs: Any) -> Response:  # type: ignore[override]\n        # Allow setting a default timeout on a session\n        kwargs.setdefault(\"timeout\", self.timeout)\n        # Allow setting a default proxies on a session\n        kwargs.setdefault(\"proxies\", self.proxies)\n\n        # Dispatch the actual request\n        try:\n            return super().request(method, url, *args, **kwargs)\n        except (requests.ConnectionError, requests.Timeout) as e:\n            request = getattr(e, \"request\", None)\n            failed_url = getattr(request, \"url\", None) or url\n            raise_connection_error(e, url=failed_url, timeout=kwargs[\"timeout\"])\n        except ImportError as e:\n            if \"ssl\" in str(e).lower():\n                # Unfortunately, if this TLS error was the result of a redirect from\n                # a HTTP to a HTTPS url, we don't know what the final url was.\n                raise SSLMissingError(redact_auth_from_url(url))\n            raise\n","sourceCodeStart":530,"sourceCodeEnd":550,"githubUrl":"https://github.com/pypa/pip/blob/f399c3718970b1b0e2478dac5296eb62679a9b86/src/pip/_internal/network/session.py#L530-L550","documentation":"Raised as SSLMissingError in PipSession.request when the underlying request to an HTTPS URL fails with an ImportError whose message mentions 'ssl'. That means the running Python interpreter was built without the _ssl/OpenSSL C extension, so HTTPS is impossible.","triggerScenarios":"Any HTTPS index/download request when Python's _ssl module is unavailable; e.g. a stripped or custom-built CPython lacking OpenSSL linkage, or a broken Python distribution where _ssl.pyd/.so failed to import.","commonSituations":"Minimal Docker/base images with hand-compiled Python missing libssl-dev; broken Python installs after an OS openssl upgrade relocated the shared lib; embedded Python distributions.","solutions":["Reinstall or rebuild Python with OpenSSL support (install libssl-dev/openssl-devel and reconfigure/recompile).","Use an official CPython distribution that bundles SSL support.","Verify with 'python -c \"import ssl\"' that the interpreter can load _ssl.","As a last resort only, point pip at an HTTP index (insecure, not recommended)."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"def python_has_ssl() -> bool:\n    try:\n        import ssl  # noqa: F401\n        return True\n    except ImportError:\n        return False\n\n# assert python_has_ssl()","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Build/install Python with OpenSSL support (libssl-dev at build time).","Use official CPython distributions that bundle SSL.","Validate 'python -c \"import ssl\"' in image build pipelines."],"tags":["ssl","tls","python-build","https"],"backgroundTag":null,"analyzedSha":"f399c3718970b1b0e2478dac5296eb62679a9b86","analyzedAt":"2026-08-08T23:01:42.227Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}