# Totalsegmentator install fails due to certificate issue

**URL:** <https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564>\
**Category:** Support\
**Created:** [March 24, 2023, 7:56pm UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564 "2023-03-24T19:56:57Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)\
**Post date:** [March 24, 2023, 7:56pm UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/1 "2023-03-24T19:56:57Z")

</div>

This is mostly an issue on our end. I managed to download the zip archive from our end. Is there a way to manually install this?  
@rbumm

```auto
Collecting https://github.com/wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
  WARNING: Retrying (Retry(total=4, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
  WARNING: Retrying (Retry(total=3, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
  WARNING: Retrying (Retry(total=2, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
  WARNING: Retrying (Retry(total=1, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
  WARNING: Retrying (Retry(total=0, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
ERROR: Could not install packages due to an OSError: HTTPSConnectionPool(host='github.com', port=443): Max retries exceeded with url: /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)')))

[notice] A new release of pip is available: 23.0 -> 23.0.1
[notice] To update, run: python-real.exe -m pip install --upgrade pip
[Python] Failed to compute results.
[Python] Command '['C:/Slicer 5.2.2/bin/../bin\\PythonSlicer.EXE', '-m', 'pip', 'install', 'https://github.com/wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip']' returned non-zero exit status 1.
Traceback (most recent call last):
  File "C:/Slicer 5.2.2/NA-MIC/Extensions-31382/TotalSegmentator/lib/Slicer-5.2/qt-scripted-modules/TotalSegmentator.py", line 255, in onApplyButton
    self.logic.setupPythonRequirements()
  File "C:/Slicer 5.2.2/NA-MIC/Extensions-31382/TotalSegmentator/lib/Slicer-5.2/qt-scripted-modules/TotalSegmentator.py", line 624, in setupPythonRequirements
    slicer.util.pip_install(self.totalSegmentatorPythonPackageDownloadUrl)
  File "C:\Slicer 5.2.2\bin\Python\slicer\util.py", line 3578, in pip_install
    _executePythonModule('pip', args)
  File "C:\Slicer 5.2.2\bin\Python\slicer\util.py", line 3540, in _executePythonModule
    logProcessOutput(proc)
  File "C:\Slicer 5.2.2\bin\Python\slicer\util.py", line 3509, in logProcessOutput
    raise CalledProcessError(retcode, proc.args, output=proc.stdout, stderr=proc.stderr)
subprocess.CalledProcessError: Command '['C:/Slicer 5.2.2/bin/../bin\\PythonSlicer.EXE', '-m', 'pip', 'install', 'https://github.com/wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip']' returned non-zero exit status 1.

```

---

<div class="post-metadata">

**Author:** ![rbumm](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/rbumm/32/9404_2.png) [@rbumm](https://discourse.slicer.org/u/rbumm)\
**Post date:** [March 25, 2023, 6:15am UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/2 "2023-03-25T06:15:21Z")

</div>

No immediate idea - How did you install TotalSegmentator? From the Python Console or through the extension? You are using Linux?

---

<div class="post-metadata">

**Author:** ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)\
**Post date:** [March 25, 2023, 6:24am UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/3 "2023-03-25T06:24:53Z")

</div>

İ installed via the extension manager (also putorch too). Pytorch threw a similar certificate error, so i downloaded the wheel and manually installed it. Pytorch works now. This is on windows.

---

<div class="post-metadata">

**Author:** ![rbumm](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/rbumm/32/9404_2.png) [@rbumm](https://discourse.slicer.org/u/rbumm)\
**Post date:** [March 25, 2023, 8:57am UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/4 "2023-03-25T08:57:33Z")

</div>

> [@muratmaga](#):
>
> `Could not install packages due to an OSError: HTTPSConnectionPool`

Could you check [this thread](https://stackoverflow.com/questions/55688358/how-to-fix-could-not-install-packages-due-to-an-environmenterror-httpsconnecti)? Are you maybe having issues with firewall settings or antivirus software? Please try to connect to a different network or use a VPN

---

<div class="post-metadata">

**Author:** ![jcfr](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/jcfr/32/17825_2.png) [@jcfr](https://discourse.slicer.org/u/jcfr)\
**Post date:** [March 25, 2023, 5:52pm UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/5 "2023-03-25T17:52:20Z")

</div>

I have been discussing similar issue in a different post where I am also providing a small python snippet to help better understand.

> [@Slicer fails to download custom sample data](https://discourse.slicer.org/t/slicer-fails-to-download-custom-sample-data/28561/10):
>
> Could you try the following ? The snippet is expected to work in both PythonSlicer and a regular python interpreter. import sys import traceback import urllib.request def processEvents(): try: import slicer slicer.app.processEvents() except (AttributeError, ImportError): pass def display(text, file=sys.stdout): processEvents() print(text, flush=True, file=file) def error(text): display(text, file=sys.stderr) for url, expected\_success …

Could you try the python snippet I provide in the following context ?

- Python console built-in the Slicer application
- PythonSlicer python console
- Regular python console outside of the Slicer environment

---

<div class="post-metadata">

**Author:** ![rbumm](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/rbumm/32/9404_2.png) [@rbumm](https://discourse.slicer.org/u/rbumm)\
**Post date:** [March 25, 2023, 7:46pm UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/6 "2023-03-25T19:46:16Z")

</div>

Windows Powershell, same in Slicer 5.2.2

```auto
--------
Checking https://data.kitware.com
Checking https://data.kitware.com - OK
--------
Checking https://www.httpvshttps.com/
Checking https://www.httpvshttps.com/ - OK
--------
Checking https://slicer.org/
Checking https://slicer.org/ - OK
--------
Checking https://expired.badssl.com/
Checking https://expired.badssl.com/ - OK [Expected <urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate has expired (_ssl.c:1129)>]
--------
Checking https://github.com/
Checking https://github.com/ - OK`

```

---

<div class="post-metadata">

**Author:** ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)\
**Post date:** [March 26, 2023, 2:51am UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/7 "2023-03-26T02:51:38Z")

</div>

> [@muratmaga](#):
>
> ```auto
> Collecting https://github.com/wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
> WARNING: Retrying (Retry(total=4, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
> WARNING: Retrying (Retry(total=3, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
> WARNING: Retrying (Retry(total=2, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
> WARNING: Retrying (Retry(total=1, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
> WARNING: Retrying (Retry(total=0, connect=None, read=None, redirect=None, status=None)) after connection broken by 'SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)'))': /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip
> ERROR: Could not install packages due to an OSError: HTTPSConnectionPool(host='github.com', port=443): Max retries exceeded with url: /wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1129)')))
> 
> ```

As a workaround, you can download the package using a web browser (from the URL that is shown in the error message) and then then `pip install` that file.

---

<div class="post-metadata">

**Author:** ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)\
**Post date:** [March 28, 2023, 4:29pm UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/8 "2023-03-28T16:29:08Z")

</div>

This is the output from python console inside the slicer

```auto
Checking https://data.kitware.com
Checking https://data.kitware.com - OK
--------
Checking https://www.httpvshttps.com/
Checking https://www.httpvshttps.com/ - OK
--------
Checking https://slicer.org/
Checking https://slicer.org/ - OK
--------
Checking https://expired.badssl.com/
Checking https://expired.badssl.com/ - OK [Expected <urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate (_ssl.c:1129)>]
--------
Checking https://github.com/
Checking https://github.com/ - OK

```

---

<div class="post-metadata">

**Author:** ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)\
**Post date:** [March 28, 2023, 4:39pm UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/10 "2023-03-28T16:39:36Z")

</div>

@lassoan

I just retried and pip\_install local zip file seemed to work this time.

But i encountered another issue. Upon invoking TotalSegmentator module, module wants to update the installation from original source (even through I installed the exact version). Of course this fails with the same certificate error as the extension based install.

---

<div class="post-metadata">

**Author:** ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)\
**Post date:** [March 28, 2023, 5:25pm UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/11 "2023-03-28T17:25:15Z")

</div>

Please check why the module wants to update. You should be able to see it from the stack trace but if it is not clear then you can attach Visual Studio Code’s debugger and step through the code.

---

<div class="post-metadata">

**Author:** ![muratmaga](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/muratmaga/32/3622_2.png) [@muratmaga](https://discourse.slicer.org/u/muratmaga)\
**Post date:** [April 3, 2023, 9:12pm UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/12 "2023-04-03T21:12:38Z")

</div>

This is from the error message if it helps:

```auto
Traceback (most recent call last):
  File "C:\Slicer 5.2.2\bin\Python\slicer\util.py", line 2967, in tryWithErrorDisplay
    yield
  File "C:/Slicer 5.2.2/NA-MIC/Extensions-31382/TotalSegmentator/lib/Slicer-5.2/qt-scripted-modules/TotalSegmentator.py", line 255, in onApplyButton
    self.logic.setupPythonRequirements()
  File "C:/Slicer 5.2.2/NA-MIC/Extensions-31382/TotalSegmentator/lib/Slicer-5.2/qt-scripted-modules/TotalSegmentator.py", line 624, in setupPythonRequirements
    slicer.util.pip_install(self.totalSegmentatorPythonPackageDownloadUrl)
  File "C:\Slicer 5.2.2\bin\Python\slicer\util.py", line 3578, in pip_install
    _executePythonModule('pip', args)
  File "C:\Slicer 5.2.2\bin\Python\slicer\util.py", line 3540, in _executePythonModule
    logProcessOutput(proc)
  File "C:\Slicer 5.2.2\bin\Python\slicer\util.py", line 3509, in logProcessOutput
    raise CalledProcessError(retcode, proc.args, output=proc.stdout, stderr=proc.stderr)
subprocess.CalledProcessError: Command '['C:/Slicer 5.2.2/bin/../bin\\PythonSlicer.EXE', '-m', 'pip', 'install', 'https://github.com/wasserth/TotalSegmentator/archive/b38eb449ad8652a987878a925203cbfa354e9b85.zip']' returned non-zero exit status 1.

```

---

<div class="post-metadata">

**Author:** ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)\
**Post date:** [April 3, 2023, 9:52pm UTC](https://discourse.slicer.org/t/totalsegmentator-install-fails-due-to-certificate-issue/28564/13 "2023-04-03T21:52:55Z")

</div>

The version of TotalSegmentator is identified by the download URL because we need to install it by URL and not by version (because it is rarely updated on PyPI and version numbers of packages not on PyPI are unreliable).

You can disable the mechanism that installs the correct TotalSegmentator version by bypassing this check:

> <https://github.com/lassoan/SlicerTotalSegmentator/blob/392c53e9f465dca07f0008495a569d077f5630bd/TotalSegmentator/TotalSegmentator.py#L640>

This will allow you to move a bit further.
