Skip to content

macOS: encrypted connections fail after Homebrew moved the openssl alias to openssl@4 #826

Description

@rgant

Describe the bug

On macOS with Homebrew, every encrypted connection fails because the bundled ODBC driver cannot load OpenSSL. The cause is Homebrew/homebrew-core#313581, which moved the openssl alias from openssl@3 to openssl@4 on 2026-09-27.

The bundled libmsodbcsql.18.dylib loads OpenSSL only from these two paths:

/opt/homebrew/opt/openssl/lib/
/usr/local/opt/openssl/lib/

In each path, it tries libssl.1.1.dylib and the unversioned libssl.dylib (from strings .../mssql_python_odbc/libs/macos/arm64/lib/libmsodbcsql.18.dylib).

On 2026-09-27, Homebrew moved the openssl alias from openssl@3 to openssl@4 in Homebrew/homebrew-core#313581. The migration is tracked in Homebrew/homebrew-core#278366. Now /opt/homebrew/opt/openssl belongs to openssl@4. When only openssl@3 is installed, brew upgrade removes the link, and the driver finds no OpenSSL.

When openssl@4 is installed, libssl.dylib in that path is OpenSSL 4. The driver loads libssl.4.dylib from the openssl@4 4.0.2_1 bottle, then refuses it with the same error. So the README install step brew install openssl now gives a setup that cannot connect.

Exception message:
mssql_python.exceptions.OperationalError: Driver Error: Client unable to establish connection; DDBC Error: [Microsoft]SSL Provider: [OpenSSL library could not be loaded, make sure OpenSSL 1.0, 1.1, or 3.0 is installed]
Stack trace:
.venv/lib/python3.14/site-packages/mssql_python/db_connection.py:89: in connect
    conn = Connection(
.venv/lib/python3.14/site-packages/mssql_python/connection.py:753: in __init__
    _raise_connection_error(e)
.venv/lib/python3.14/site-packages/mssql_python/connection.py:125: in _raise_connection_error
    raise exc from None

To reproduce

Case A, only OpenSSL 3:

  1. On Apple silicon, install openssl@3 with Homebrew, and do not install openssl@4.
  2. Confirm that /opt/homebrew/opt/openssl does not exist.
  3. Run the code below.

Case B, OpenSSL 4:

  1. Run brew install openssl, as the README says. This installs openssl@4.
  2. Run the code below. DYLD_PRINT_LIBRARIES=1 shows libssl.4.dylib load before the error.
from mssql_python import connect

connect("Server=tcp:<server>.database.windows.net,1433;Database=<database>;Encrypt=yes;Authentication=ActiveDirectoryDefault")

Workaround: ln -s openssl@3 /opt/homebrew/opt/openssl. After that, the connection succeeds.

Expected behavior

The driver connects with the OpenSSL that Homebrew's openssl installs now, which is OpenSSL 4. If the driver cannot support OpenSSL 4, it finds OpenSSL 3 from openssl@3, for example at /opt/homebrew/opt/openssl@3/lib/, and the README names openssl@3.

Further technical details

Python version: 3.14.7
SQL Server version: Azure SQL Database (serverless)
Operating system: macOS 27.0, arm64
mssql-python: 1.15.0
mssql-python-odbc: 18.6.2.1
Homebrew: 7.0.7, openssl@3 3.6.4_1

Additional context

A later install of openssl@4, for example as a dependency of another formula, takes the openssl link back. Then the driver loads OpenSSL 4 and fails as in case B.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area: packaging-platformWheels, version support, OS/arch coverage (Linux/macOS/Windows), install or import failures.bugSomething isn't workingtriage neededFor new issues, not triaged yet.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions