pip: "Can't Connect to HTTPS URL because the SSL Module Is Not Available"

Your Python was built without working OpenSSL bindings — typical for source builds, pyenv on newer distros, or an interpreter built against a dev package that isn't installed. Reinstalling the interpreter (not pip) fixes it.

What you'll see

Root causes

Python built without OpenSSL headers or against an incompatible OpenSSL

Source builds link libssl at compile time: missing libssl-dev (Debian) or a mismatched OpenSSL version (CentOS 1.0 vs Python needing 1.1+) leaves the ssl module absent. python -c 'import ssl' fails.

Pyenv on distros without build deps

pyenv install compiles from source: without openssl-devel and friends, the build succeeds minus TLS, and every pip network call dies. Same signature, same fix class.

Fix it

  1. Confirm the interpreter itself lacks ssl
    python -c 'import ssl' 2>&1 ; python -c 'import _ssl' 2>&1 | tail -1
  2. Install the OpenSSL build dependencies
    sudo apt install -y libssl-dev zlib1g-dev libbz2-dev libreadline-dev libsqlite3-dev  # Debian/Ubuntu
  3. Rebuild/reinstall the interpreter
    pyenv install <version>   # or for source: ./configure --with-ensurepip=install && make && sudo make altinstall
  4. Prefer distro/system Python when TLS matters and you don't control the toolchain
    sudo apt install python3 python3-pip python3-venv   # linked correctly by the distro maintainers

Field note

This is an interpreter problem, not a pip problem: no pip flag fixes a Python without TLS. Reinstall the interpreter after fixing the dev packages. python -c 'import ssl' is the 5-second test before any deeper debugging — the output distinguishes missing-module (rebuild) from import errors (environment).

Common questions

Can I install a wheel manually to work around it?

You can install wheels, but without ssl the interpreter is permanently hobbled: https, TLS, hashlib features all misbehave. Fix the build once and everything downstream heals.

Why did pyenv's install succeed if it was broken?

The compile logs a warning about the missing ssl module but still completes. Nobody reads build logs on success — which is exactly why this error appears later, at first pip use.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.