python network_error ai_generated true

aiohttp.client_exceptions.ClientConnectorCertificateError: 无法连接到主机 example.com:443 ssl:True [SSLCertVerificationError: 证书验证失败: 无法获取本地颁发者证书]

aiohttp.client_exceptions.ClientConnectorCertificateError: Cannot connect to host example.com:443 ssl:True [SSLCertVerificationError: certificate verify failed: unable to get local issuer certificate]

ID: python/aiohttp-connector-ssl-error

其他格式: JSON · Markdown 中文 · English
80%修复率
87%置信度
0证据数
2024-02-18首次发现

版本兼容性

版本状态引入弃用备注
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

根因分析

aiohttp 通过 Python 的 ssl 模块使用系统 CA 证书;在某些平台(macOS 官方 python.org 构建、精简版 Docker 镜像)上,CA 存储缺失或过期。

English

aiohttp uses the system CA bundle via Python's ssl module; on some platforms (macOS python.org builds, minimal Docker images) the CA store is missing or outdated.

generic

解决方案

  1. 92% 成功率
    Install certifi and pass its CA bundle:
    
    import ssl, certifi
    ctx = ssl.create_default_context(cafile=certifi.where())
    async with aiohttp.ClientSession() as s:
        await s.get(url, ssl=ctx)
  2. 90% 成功率
    On macOS, run the 'Install Certificates.command' shipped with python.org installers.
  3. 95% 成功率
    In Docker, apt-get install -y ca-certificates and run update-ca-certificates in the image build.

无效尝试

常见但无效的做法:

  1. 20% 失败

    Disables TLS verification entirely, exposing the app to MITM; not acceptable in production.

  2. 75% 失败

    Only affects urllib/http.client, not aiohttp's SSL context.

  3. 85% 失败

    The library is not the problem; the CA bundle is.