python network_error ai_generated true

aiohttp.client_exceptions.ClientConnectorCertificateError: Cannot connect to host example.com:443 ssl:True [SSLCertVerificationError: certificate verify failed: unable to get local issuer certificate]

ID: python/aiohttp-connector-ssl-error

Also available as: JSON · Markdown · 中文
80%Fix Rate
87%Confidence
0Evidence
2024-02-18First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

Root Cause

aiohttp uses the system CA bundle via Python's ssl module; on some platforms (macOS python.org builds, minimal Docker images) the CA store is missing or outdated.

generic

中文

aiohttp 通过 Python 的 ssl 模块使用系统 CA 证书;在某些平台(macOS 官方 python.org 构建、精简版 Docker 镜像)上,CA 存储缺失或过期。

Workarounds

  1. 92% success
    Install certifi and pass its CA bundle:
    
    import ssl, certifi
    ctx = ssl.create_default_context(cafile=certifi.where())
    async with aiohttp.ClientSession() as s:
        await s.get(url, ssl=ctx)
  2. 90% success
    On macOS, run the 'Install Certificates.command' shipped with python.org installers.
  3. 95% success
    In Docker, apt-get install -y ca-certificates and run update-ca-certificates in the image build.

Dead Ends

Common approaches that don't work:

  1. 20% fail

    Disables TLS verification entirely, exposing the app to MITM; not acceptable in production.

  2. 75% fail

    Only affects urllib/http.client, not aiohttp's SSL context.

  3. 85% fail

    The library is not the problem; the CA bundle is.