{"record":{"id":"71487353ecf56bac","repo":"aio-libs/aiohttp","slug":"cannot-connect-to-host-host-port-ssl-ssl-s","errorCode":null,"errorMessage":"Cannot connect to host {host}:{port} ssl:{ssl} [{strerror}]","messagePattern":"Cannot connect to host (.+?):(.+?) ssl:(.+?) \\[(.+?)\\]","errorType":"exception","errorClass":"ClientConnectorSSLError","httpStatus":null,"severity":"error","filePath":"aiohttp/connector.py","lineNumber":1349,"sourceCode":"                    addr_infos=addr_infos,\n                    local_addr_infos=self._local_addr_infos,\n                    happy_eyeballs_delay=self._happy_eyeballs_delay,\n                    interleave=self._interleave,\n                    loop=self._loop,\n                    socket_factory=self._socket_factory,\n                )\n                # Add ssl_shutdown_timeout for Python 3.11+ when SSL is used\n                if (\n                    kwargs.get(\"ssl\")\n                    and self._ssl_shutdown_timeout\n                    and sys.version_info >= (3, 11)\n                ):\n                    kwargs[\"ssl_shutdown_timeout\"] = self._ssl_shutdown_timeout\n                return await create_connection(self._loop, *args, **kwargs, sock=sock)\n        except cert_errors as exc:\n            raise ClientConnectorCertificateError(req.connection_key, exc) from exc\n        except ssl_errors as exc:\n            raise ClientConnectorSSLError(req.connection_key, exc) from exc\n        except OSError as exc:\n            if exc.errno is None and isinstance(exc, asyncio.TimeoutError):\n                raise\n            raise client_error(req.connection_key, exc) from exc\n\n    def _warn_about_tls_in_tls(\n        self,\n        underlying_transport: asyncio.Transport,\n        req: ClientRequest,\n    ) -> None:\n        \"\"\"Issue a warning if the requested URL has HTTPS scheme.\"\"\"\n        if req.url.scheme != \"https\":\n            return\n\n        # TLS-in-TLS only applies when the proxy itself is HTTPS.\n        # When the proxy is HTTP, start_tls upgrades a plain TCP connection,\n        # which is standard TLS and works on all event loops and Python versions.\n        if req.proxy is None or req.proxy.scheme != \"https\":","sourceCodeStart":1331,"sourceCodeEnd":1367,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/connector.py#L1331-L1367","documentation":"Raised by _wrap_create_connection during a direct (non-proxy) connect when the TLS handshake or socket setup fails with an SSL error that is not a certificate error (ssl_errors branch) or with an OSError surfaced as a generic connector error. ClientConnectorSSLError covers protocol-level TLS failures (e.g. no common cipher, TLS version mismatch, handshake EOF); the OSError path produces a ClientConnectorError whose __str__ formats the strerror.","triggerScenarios":"Server only supports TLS versions the client does not offer; cipher-suite negotiation fails; middlebox truncates the handshake; port 443 reachable but speaking plain HTTP; SNI required and not sent; firewall RST during handshake.","commonSituations":"Modern client hitting a legacy TLS 1.0-only server (or vice versa); corporate TLS-intercepting proxy with a broken chain; network path with aggressive RST injection; wrong scheme against a non-TLS port.","solutions":["Confirm scheme/port: HTTPS on 443, and that the endpoint actually speaks TLS.","If TLS version mismatch is confirmed, configure an ssl.SSLContext that enables the required version (temporary, scoped).","Check for TLS-intercepting middleboxes and add their CA if intentional.","Use openssl s_client -connect host:port to reproduce the handshake failure outside aiohttp."],"exampleFix":"# before\nawait session.get('https://legacy.corp:443/')\n# after - diagnose, then enable the missing protocol if acceptable\nimport ssl\nctx = ssl.create_default_context()\nctx.minimum_version = ssl.TLSVersion.TLSv1_2  # match what the server supports\nasync with aiohttp.ClientSession(connector=aiohttp.TCPConnector(ssl=ctx)) as s:\n    await s.get('https://legacy.corp/')","handlingStrategy":"try-catch","validationCode":"import ssl\n\ndef compatible_context(minimum=ssl.TLSVersion.TLSv1_2):\n    ctx = ssl.create_default_context()\n    ctx.minimum_version = minimum\n    return ctx","typeGuard":"null","tryCatchPattern":"try:\n    resp = await session.get(url)\nexcept aiohttp.ClientConnectorSSLError as exc:\n    log.error('TLS failure for %s: %s', url, exc)\n    raise\nexcept aiohttp.ClientConnectorError as exc:\n    log.error('connection failure for %s: %s', url, exc.os_error)\n    raise","preventionTips":["Confirm the endpoint actually speaks TLS on the target port before assuming cert issues.","Reproduce handshake problems with openssl s_client outside the app.","Keep the OpenSSL/SSLContext up to date so modern protocols are negotiable."],"tags":["ssl","connection","handshake","client-connector"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}