aiohttp.client_exceptions.ClientConnectorCertificateError: 无法连接到主机 example.com:443 ssl:True [SSLCertVerificationError: (1, '[SSL: CERTIFICATE_VERIFY_FAILED] 证书验证失败:无法获取本地颁发者证书 (_ssl.c:1007)')]
aiohttp.client_exceptions.ClientConnectorCertificateError: Cannot connect to host example.com:443 ssl:True [SSLCertVerificationError: (1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1007)')]
ID: python/aiohttp-connector-ssl-certificate-error
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| 3.8 | active | — | — | — |
| 3.9 | active | — | — | — |
| 3.10 | active | — | — | — |
| 3.11 | active | — | — | — |
| 3.12 | active | — | — | — |
根因分析
服务器提供的 TLS 证书链无法用 Python 可用的 CA 包验证,通常是由于缺少中间证书或 certifi 包过时。
English
The TLS certificate chain presented by the server cannot be verified against the CA bundle available to Python, often due to a missing intermediate certificate or an outdated certifi package.
解决方案
-
88% 成功率
pip install --upgrade certifi import ssl, certifi, aiohttp ctx = ssl.create_default_context(cafile=certifi.where()) conn = aiohttp.TCPConnector(ssl=ctx) async with aiohttp.ClientSession(connector=conn) as s: await s.get(url) -
85% 成功率
ctx = ssl.create_default_context(cafile='/etc/ssl/certs/ca-certificates.crt') conn = aiohttp.TCPConnector(ssl=ctx) # use conn in ClientSession
无效尝试
常见但无效的做法:
-
90% 失败
Disables security entirely and is rejected in production; also masks the real missing-CA problem.
-
95% 失败
Certificate verification is deterministic; retries hit the same SSLCertVerificationError.