$npx skillfedfor your agent

certifi-linux

Certifi patch for using Linux cert trust stores

With conditionsPyPI CryptographyReleased May 2025171.5K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — certifi_linux-1.1.0-py3-none-any.whl
v1.1.0 · released 2025-05-27 · Python >=3.7 · 1 runtime deps: wrapt

Yes, if you are on Linux and need Python applications to respect the system certificate store. The install is frictionless, maintenance is active, and there are no known vulnerabilities. Not applicable on Windows or other non-Linux platforms. Verify that your Linux distribution's certificate path is among the tested ones before relying on it in production.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Linux-only; will not work on Windows, macOS, or other non-Linux platforms.
  • Requires one of the tested certificate bundle paths to exist on the system.
  • Low friction install with a single runtime dependency (wrapt).

License · maintenance · safety

permissive license (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal legal friction.

last release 2025-05-27 (444 days) · last repo commit 2026-08-11 · 4 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 171,515 downloads/mo, #10,363 on PyPI

Verify before relying

pip install certifi-linux

# Then in any code using certifi:
import certifi
print(certifi.where())  # Now returns system cert path, e.g. /etc/ssl/certs/ca-certificates.crt
  • Whether the package successfully handles all untested distributions (Arch, Slackware, OpenWRT, FreeBSD, SUSE, gentoo) or only the documented ones.
  • Performance impact of certificate path searching at runtime compared to direct bundled-certificate lookup.
  • Behavior when multiple certificate bundle paths exist on the same system.
Same gist for agents: .md · .json

What it is and what it does

certifi-linux is a monkey-patch wrapper around certifi that intercepts calls to certifi.where() and certifi.contents to return paths from the Linux system certificate store instead of bundled certificates. It uses wrapt to inject this behavior transparently, so any library depending on certifi automatically uses OS-managed certificates without code changes.

This is particularly useful in enterprise environments where custom or internal certificate authorities must be trusted, or where system administrators manage certificates centrally. The package searches a predefined set of common certificate bundle locations across different Linux distributions (Debian, Ubuntu, Fedora, RHEL, Alpine, CentOS) and returns the first match it finds. Installation is passive: once installed, it takes effect immediately for any downstream code that calls certifi.

Use it for

  • Enterprise deployments where internal certificate authorities must be trusted by Python applications without modifying application code.
  • Containerized applications on Linux where the host's certificate store is mounted and must be used for TLS verification.
  • Development environments on Linux where system-wide certificate updates should automatically propagate to Python's certifi lookups.
  • Compliance scenarios requiring audit trails of certificate changes managed at the OS level rather than bundled with Python packages.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are on Linux and need Python applications to respect the system certificate store.

The install is frictionless, maintenance is active, and there are no known vulnerabilities. Not applicable on Windows or other non-Linux platforms. Verify that your Linux distribution's certificate path is among the tested ones before relying on it in production.

Install

certifi-linux on PyPI

Before you install

Low friction install with a single runtime dependency (wrapt). Actively maintained as of 2026-08-11 with stable status and broad Python version support (3.7–3.13).

Linux-only; will not work on Windows, macOS, or other non-Linux platforms. Requires one of the tested certificate bundle paths to exist on the system.

License in practice

MIT license permits unrestricted use, modification, and distribution with minimal legal friction.

Quickstart

pip install certifi-linux

# Then in any code using certifi:
import certifi
print(certifi.where())  # Now returns system cert path, e.g. /etc/ssl/certs/ca-certificates.crt

Verify before relying

  • Whether the package successfully handles all untested distributions (Arch, Slackware, OpenWRT, FreeBSD, SUSE, gentoo) or only the documented ones.
  • Performance impact of certificate path searching at runtime compared to direct bundled-certificate lookup.
  • Behavior when multiple certificate bundle paths exist on the same system.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.7
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
wrapt
MaintenanceActively maintained 444 days since the last release
Last repo commit
First released
Downloads171,515 / month, #10,363 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableLicense :: OSI Approved :: MIT LicenseOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPython

Evidence: certifi_linux-1.1.0-py3-none-any.whl

Tags

Capabilities
linux system certificatescertifi system trust storeos certificate bundleenterprise ssl certificateslinux ca certificatestls certificate overridesystem certificate path
Topics
certificate-managementlinux-system-integrationenterprise-ssl
PyPI keywords
certificertificatescertslinuxrequestsssltls

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “linux system certificates”

  • certifi-linuxRedirects certifi's certificate lookup to use the Linux system trust…
  • truststoreTruststore exposes native system certificate stores through an SSL…
  • certbot-nginxCertbot-nginx is a plugin for Certbot that automates obtaining and…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also python-certifi-win32 · trustme · wassima · wincertstore · pip-system-certs · truststore · certipy · bindep · mscerts