# aiohttp.client_exceptions.ClientConnectorCertificateError: Cannot connect to host example.com:443 ssl:True [SSLCertVerificationError: certificate verify failed: unable to get local issuer certificate]

- **ID:** `python/aiohttp-connector-ssl-error`
- **Domain:** python
- **Category:** network_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

aiohttp uses the system CA bundle via Python's ssl module; on some platforms (macOS python.org builds, minimal Docker images) the CA store is missing or outdated.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## Workarounds

1. **** (92% success)
   ```
   Install certifi and pass its CA bundle:

import ssl, certifi
ctx = ssl.create_default_context(cafile=certifi.where())
async with aiohttp.ClientSession() as s:
    await s.get(url, ssl=ctx)
   ```
2. **** (90% success)
   ```
   On macOS, run the 'Install Certificates.command' shipped with python.org installers.
   ```
3. **** (95% success)
   ```
   In Docker, apt-get install -y ca-certificates and run update-ca-certificates in the image build.
   ```

## Dead Ends

- **** — Disables TLS verification entirely, exposing the app to MITM; not acceptable in production. (20% fail)
- **** — Only affects urllib/http.client, not aiohttp's SSL context. (75% fail)
- **** — The library is not the problem; the CA bundle is. (85% fail)
