python network_error ai_generated true

aiohttp.client_exceptions.ClientConnectorCertificateError: Cannot connect to host example.com:443 ssl:True [SSLCertVerificationError: (1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1007)')]

ID: python/aiohttp-connector-ssl-certificate-error

Also available as: JSON · Markdown · 中文
80%Fix Rate
86%Confidence
0Evidence
2024-04-08First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

Root Cause

The TLS certificate chain presented by the server cannot be verified against the CA bundle available to Python, often due to a missing intermediate certificate or an outdated certifi package.

generic

中文

服务器提供的 TLS 证书链无法用 Python 可用的 CA 包验证,通常是由于缺少中间证书或 certifi 包过时。

Workarounds

  1. 88% success
    pip install --upgrade certifi
    import ssl, certifi, aiohttp
    ctx = ssl.create_default_context(cafile=certifi.where())
    conn = aiohttp.TCPConnector(ssl=ctx)
    async with aiohttp.ClientSession(connector=conn) as s:
        await s.get(url)
  2. 85% success
    ctx = ssl.create_default_context(cafile='/etc/ssl/certs/ca-certificates.crt')
    conn = aiohttp.TCPConnector(ssl=ctx)
    # use conn in ClientSession

Dead Ends

Common approaches that don't work:

  1. 90% fail

    Disables security entirely and is rejected in production; also masks the real missing-CA problem.

  2. 95% fail

    Certificate verification is deterministic; retries hit the same SSLCertVerificationError.