Skip to content

Add certifi fallback for SSL certificate issues - #1732

Closed
monolith-jaehoon wants to merge 3 commits into
slackapi:mainfrom
monolith-jaehoon:feature-#1491
Closed

Add certifi fallback for SSL certificate issues#1732
monolith-jaehoon wants to merge 3 commits into
slackapi:mainfrom
monolith-jaehoon:feature-#1491

Conversation

@monolith-jaehoon

Copy link
Copy Markdown

Using Claude 4 Sonnet

Summary

Testing

  • Install Windows 11 and remain offline from internet
    • Or remove ISRG Root X1 certificate in OS
  • Install and Use Slack SDK

Category

  • slack_sdk.web.WebClient (sync/async) (Web API client)
  • slack_sdk.webhook.WebhookClient (sync/async) (Incoming Webhook, response_url sender)
  • slack_sdk.socket_mode (Socket Mode client)
  • slack_sdk.signature (Request Signature Verifier)
  • slack_sdk.oauth (OAuth Flow Utilities)
  • slack_sdk.models (UI component builders)
  • slack_sdk.scim (SCIM API client)
  • slack_sdk.audit_logs (Audit Logs API client)
  • slack_sdk.rtm_v2 (RTM client)
  • /docs (Documents)
  • /tutorial (PythOnBoardingBot tutorial)
  • tests/integration_tests (Automated tests for this library)

Requirements

  • I've read and understood the Contributing Guidelines and have done my best effort to follow them.
  • I've read and agree to the Code of Conduct.
  • I've run python3 -m venv .venv && source .venv/bin/activate && ./scripts/run_validation.sh after making the changes.

@salesforce-cla

Copy link
Copy Markdown

Thanks for the contribution! Before we can merge this, we need @monolith-jaehoon to sign the Salesforce Inc. Contributor License Agreement.

@WilliamBergamin

Copy link
Copy Markdown
Contributor

Thanks for the PR @monolith-jaehoon, and for taking the time to implement this.

This change is tied directly to #1491, and the maintainers haven't reached a decision there yet: whether to adopt certifi at all (as a default or as an optional fallback) is still an open question. Since this PR depends on that call, we're going to close it for now rather than merge ahead of the decision. If we do decide to move forward, we'll pick the discussion back up in #1491.

In the meantime, the recommended path for anyone hitting CERTIFICATE_VERIFY_FAILED is the opt-in workaround from the issue: supply your own SSL context built from certifi:

import os
import ssl
import certifi
from slack_sdk import WebClient

ssl_context = ssl.create_default_context(cafile=certifi.where())
client = WebClient(token=os.environ["SLACK_BOT_TOKEN"], ssl=ssl_context)

Really appreciate the contribution, and thanks for understanding! 🙏 We can always reopen this PR in the future

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants