# ERROR: The index URL 'http://pypi.example.com/simple' is not secure. pip requires HTTPS for all index URLs by default.

- **ID:** `python/pip-index-url-http-blocked`
- **Domain:** python
- **Category:** config_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

pip refuses plain HTTP index URLs unless explicitly trusted. Internal mirrors are often HTTP-only, so pip blocks them to prevent MITM tampering.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## Workarounds

1. **** (95% success)
   ```
   pip install --index-url http://pypi.example.com/simple --trusted-host pypi.example.com package
   ```
2. **** (92% success)
   ```
   pip config set global.trusted-host pypi.example.com && pip config set global.index-url http://pypi.example.com/simple
   ```
3. **** (98% success)
   ```
   Configure the mirror with a valid TLS cert; then use https:// URL
   ```

## Dead Ends

- **** — pip still refuses unless --trusted-host is added. (95% fail)
- **** — Same rejection; the env var does not imply trust. (90% fail)
