"no certificate or crl found" when supplying PEM file constructed from string
04:28 14 Nov 2025

I am using a known-to-be-valid PEM certificate for the purposes of calling an HTTP proxy using Python requests, but since I am in a serverless function environment, I want to create the PEM file in-memory via an environment variable (stored as a string), rather than a file stored on the container. To do that, I have the following code to re-construct the PEM file's contents:

pem_string = os.environ['PEM_STRING']
pem_string.replace(' ', '\n')
pem_string = f'-----BEGIN CERTIFICATE-----\n{pem_string}\n-----END CERTIFICATE-----\n'

Where pem_string is the encoded portion of the PEM file's contents, except when stored as an env var, it loses all of the newlines so I need to inject them back in using the above example.

Next, I write this to a temp file, and then supply the temp file to Python requests vi the "verify" parameter to hopefully get the certificate to work:

with tempfile.NamedTemporaryFile(mode='w', delete=False, suffix='.pem') as cert_file:
    cert_file.write(pem_string)
    with requests.get(url, stream=True, verify=cert_file.name, proxies=proxies) as req:
        # Handle the request

Unfortunately this results in the error

SSLError("unable to load trusted certificates: Error([('x509 certificate routines', '', 'no certificate or crl found')])")

Can someone help me understand if I am doing anything incorrectly here?

python ssl ssl-certificate pem