# aiohttp.client_exceptions.ClientConnectorCertificateError: 无法连接到主机 example.com:443 ssl:True [SSLCertVerificationError: (1, '[SSL: CERTIFICATE_VERIFY_FAILED] 证书验证失败：无法获取本地颁发者证书 (_ssl.c:1007)')]

- **ID:** `python/aiohttp-connector-ssl-certificate-error`
- **领域:** python
- **类别:** network_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

服务器提供的 TLS 证书链无法用 Python 可用的 CA 包验证，通常是由于缺少中间证书或 certifi 包过时。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## 解决方案

1. **** (88% 成功率)
   ```
   pip install --upgrade certifi
import ssl, certifi, aiohttp
ctx = ssl.create_default_context(cafile=certifi.where())
conn = aiohttp.TCPConnector(ssl=ctx)
async with aiohttp.ClientSession(connector=conn) as s:
    await s.get(url)
   ```
2. **** (85% 成功率)
   ```
   ctx = ssl.create_default_context(cafile='/etc/ssl/certs/ca-certificates.crt')
conn = aiohttp.TCPConnector(ssl=ctx)
# use conn in ClientSession
   ```

## 无效尝试

- **** — Disables security entirely and is rejected in production; also masks the real missing-CA problem. (90% 失败率)
- **** — Certificate verification is deterministic; retries hit the same SSLCertVerificationError. (95% 失败率)
