python network_error ai_generated true

aiohttp.client_exceptions.ClientConnectorCertificateError: 无法连接到主机 example.com:443 ssl:True [SSLCertVerificationError: (1, '[SSL: CERTIFICATE_VERIFY_FAILED] 证书验证失败:无法获取本地颁发者证书 (_ssl.c:1007)')]

aiohttp.client_exceptions.ClientConnectorCertificateError: Cannot connect to host example.com:443 ssl:True [SSLCertVerificationError: (1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1007)')]

ID: python/aiohttp-connector-ssl-certificate-error

其他格式: JSON · Markdown 中文 · English
80%修复率
86%置信度
0证据数
2024-04-08首次发现

版本兼容性

版本状态引入弃用备注
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

根因分析

服务器提供的 TLS 证书链无法用 Python 可用的 CA 包验证,通常是由于缺少中间证书或 certifi 包过时。

English

The TLS certificate chain presented by the server cannot be verified against the CA bundle available to Python, often due to a missing intermediate certificate or an outdated certifi package.

generic

解决方案

  1. 88% 成功率
    pip install --upgrade certifi
    import ssl, certifi, aiohttp
    ctx = ssl.create_default_context(cafile=certifi.where())
    conn = aiohttp.TCPConnector(ssl=ctx)
    async with aiohttp.ClientSession(connector=conn) as s:
        await s.get(url)
  2. 85% 成功率
    ctx = ssl.create_default_context(cafile='/etc/ssl/certs/ca-certificates.crt')
    conn = aiohttp.TCPConnector(ssl=ctx)
    # use conn in ClientSession

无效尝试

常见但无效的做法:

  1. 90% 失败

    Disables security entirely and is rejected in production; also masks the real missing-CA problem.

  2. 95% 失败

    Certificate verification is deterministic; retries hit the same SSLCertVerificationError.