# aiohttp.client_exceptions.ClientConnectorCertificateError: Cannot connect to host example.com:443 ssl:True [SSLCertVerificationError: (1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1007)')]

- **ID:** `python/aiohttp-connector-ssl-certificate-error`
- **Domain:** python
- **Category:** network_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

The TLS certificate chain presented by the server cannot be verified against the CA bundle available to Python, often due to a missing intermediate certificate or an outdated certifi package.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## Workarounds

1. **** (88% success)
   ```
   pip install --upgrade certifi
import ssl, certifi, aiohttp
ctx = ssl.create_default_context(cafile=certifi.where())
conn = aiohttp.TCPConnector(ssl=ctx)
async with aiohttp.ClientSession(connector=conn) as s:
    await s.get(url)
   ```
2. **** (85% success)
   ```
   ctx = ssl.create_default_context(cafile='/etc/ssl/certs/ca-certificates.crt')
conn = aiohttp.TCPConnector(ssl=ctx)
# use conn in ClientSession
   ```

## Dead Ends

- **** — Disables security entirely and is rejected in production; also masks the real missing-CA problem. (90% fail)
- **** — Certificate verification is deterministic; retries hit the same SSLCertVerificationError. (95% fail)
