
Pip uses its own bundled CA certificate store (from certifi) embedded in its _vendor package—not the system’s trust store—making it essential to know the exact path for debugging SSL issues or custom certificate injection.
pip uses its own bundled ca certificate store (from `certifi`) embedded in its `_vendor` package—not the system’s trust store—making it essential to know the exact path for debugging ssl issues or custom certificate injection.
Pip does not rely on the system’s certificate store (e.g., /etc/ssl/certs/ca-certificates.crt on Debian/Ubuntu or Keychain on macOS). Instead, it bundles a curated, up-to-date CA certificate bundle from the certifi project directly within its internal _vendor module. Even when certifi is not installed globally (as commonly seen in minimal Docker images like python:3.10), pip still works because it carries its own copy.
To locate the exact path of the CA bundle pip uses:
-
First, find pip’s installation location:
python -c "import pip; print(pip.__file__)"
This typically points to something like /usr/local/lib/python3.10/site-packages/pip/__init__.py.
-
Then derive the CA bundle path — it resides at:
<pip-site-packages-root>/pip/_vendor/certifi/cacert.pem</pip-site-packages-root>
For example:
# In a standard Python 3.10 Docker container: $ python -c "import pip; import os; print(os.path.join(os.path.dirname(pip.__file__), '_vendor', 'certifi', 'cacert.pem'))" /usr/local/lib/python3.10/site-packages/pip/_vendor/certifi/cacert.pem
✅ You can verify the file exists and inspect it:
ls -l /usr/local/lib/python3.10/site-packages/pip/_vendor/certifi/cacert.pem head -n 3 /usr/local/lib/python3.10/site-packages/pip/_vendor/certifi/cacert.pem
⚠️ Important notes:
- This path is not configurable via environment variables like SSL_CERT_FILE for pip’s internal HTTPS calls — those are hardcoded to use the bundled cert. However, tools like requests (when used separately) will respect SSL_CERT_FILE or REQUESTS_CA_BUNDLE.
- Modifying cacert.pem manually is not recommended, as it will be overwritten on pip upgrades. For enterprise environments requiring custom CAs, prefer using --trusted-host (insecure, avoid in production) or configure pip.conf with global.trusted-host only for internal indexes — better yet, inject your CA into the base image or use pip install --cert /path/to/your-bundle.pem.
- To confirm which bundle pip is actively using at runtime, you can also inspect pip’s internal logic:
python -c "from pip._vendor.certifi import where; print(where())"
This works because pip vendors certifi and exposes where() — and returns the same cacert.pem path.
In summary: pip’s CA bundle lives inside its vendored certifi, and the canonical way to resolve it is via pip._vendor.certifi.where() — a reliable, cross-platform, version-resilient method.











