# aiohttp.client_exceptions.ClientConnectorCertificateError: 无法连接到主机 example.com:443 ssl:True [SSLCertVerificationError: 证书验证失败: 无法获取本地颁发者证书]

- **ID:** `python/aiohttp-connector-ssl-error`
- **领域:** python
- **类别:** network_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

aiohttp 通过 Python 的 ssl 模块使用系统 CA 证书；在某些平台（macOS 官方 python.org 构建、精简版 Docker 镜像）上，CA 存储缺失或过期。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## 解决方案

1. **** (92% 成功率)
   ```
   Install certifi and pass its CA bundle:

import ssl, certifi
ctx = ssl.create_default_context(cafile=certifi.where())
async with aiohttp.ClientSession() as s:
    await s.get(url, ssl=ctx)
   ```
2. **** (90% 成功率)
   ```
   On macOS, run the 'Install Certificates.command' shipped with python.org installers.
   ```
3. **** (95% 成功率)
   ```
   In Docker, apt-get install -y ca-certificates and run update-ca-certificates in the image build.
   ```

## 无效尝试

- **** — Disables TLS verification entirely, exposing the app to MITM; not acceptable in production. (20% 失败率)
- **** — Only affects urllib/http.client, not aiohttp's SSL context. (75% 失败率)
- **** — The library is not the problem; the CA bundle is. (85% 失败率)
