{"record":{"id":"d5b3a707cdd226f6","repo":"aio-libs/aiohttp","slug":"cannot-connect-to-host-host-port-ssl-ssl-c","errorCode":null,"errorMessage":"Cannot connect to host {host}:{port} ssl:{ssl} [{certificate_error.__class__.__name__}: {certificate_error.args}]","messagePattern":"Cannot connect to host (.+?):(.+?) ssl:(.+?) \\[(.+?): (.+?)\\]","errorType":"exception","errorClass":"ClientConnectorCertificateError","httpStatus":null,"severity":"error","filePath":"aiohttp/connector.py","lineNumber":1347,"sourceCode":"            ):\n                sock = await aiohappyeyeballs.start_connection(\n                    addr_infos=addr_infos,\n                    local_addr_infos=self._local_addr_infos,\n                    happy_eyeballs_delay=self._happy_eyeballs_delay,\n                    interleave=self._interleave,\n                    loop=self._loop,\n                    socket_factory=self._socket_factory,\n                )\n                # Add ssl_shutdown_timeout for Python 3.11+ when SSL is used\n                if (\n                    kwargs.get(\"ssl\")\n                    and self._ssl_shutdown_timeout\n                    and sys.version_info >= (3, 11)\n                ):\n                    kwargs[\"ssl_shutdown_timeout\"] = self._ssl_shutdown_timeout\n                return await create_connection(self._loop, *args, **kwargs, sock=sock)\n        except cert_errors as exc:\n            raise ClientConnectorCertificateError(req.connection_key, exc) from exc\n        except ssl_errors as exc:\n            raise ClientConnectorSSLError(req.connection_key, exc) from exc\n        except OSError as exc:\n            if exc.errno is None and isinstance(exc, asyncio.TimeoutError):\n                raise\n            raise client_error(req.connection_key, exc) from exc\n\n    def _warn_about_tls_in_tls(\n        self,\n        underlying_transport: asyncio.Transport,\n        req: ClientRequest,\n    ) -> None:\n        \"\"\"Issue a warning if the requested URL has HTTPS scheme.\"\"\"\n        if req.url.scheme != \"https\":\n            return\n\n        # TLS-in-TLS only applies when the proxy itself is HTTPS.\n        # When the proxy is HTTP, start_tls upgrades a plain TCP connection,","sourceCodeStart":1329,"sourceCodeEnd":1365,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/connector.py#L1329-L1365","documentation":"Raised by _wrap_create_connection during a direct (non-proxy) TCP+TLS connect when the SSL handshake raises a certificate error (ssl.CertificateError or one of the cert_errors subclasses). aiohttp wraps the underlying failure in ClientConnectorCertificateError so callers can distinguish certificate problems from generic connection errors. The message echoes the original exception class and args so the CA/hostname/expiry cause is visible.","triggerScenarios":"Server presents a self-signed or expired certificate; hostname on the cert does not match req.url.host; missing intermediate certificate; client's CA bundle does not trust the issuer; client clock skewed so a valid cert appears expired/not-yet-valid.","commonSituations":"Hitting internal services with private CAs without installing the CA; staging environments with self-signed certs; containers missing ca-certificates; system time wrong in VMs; certificate renewal lapsed.","solutions":["Build an ssl.SSLContext with load_verify_locations(cafile=...) pointing at the correct CA and pass it to the connector/session.","Refresh the system CA bundle (install ca-certificates, run update-ca-certificates).","Verify system clock (NTP) so cert validity windows are evaluated correctly.","For diagnostics only, ssl=False disables verification - never use in production."],"exampleFix":"# before\nawait session.get('https://internal.corp/')\n# after\nimport ssl\nctx = ssl.create_default_context(cafile='/etc/ssl/internal-ca.pem')\nconnector = aiohttp.TCPConnector(ssl=ctx)\nasync with aiohttp.ClientSession(connector=connector) as s:\n    await s.get('https://internal.corp/')","handlingStrategy":"try-catch","validationCode":"import ssl\n\ndef trusted_context(cafile):\n    ctx = ssl.create_default_context(cafile=cafile)\n    return ctx\n\n# preflight: ensure the host's cert chains to the supplied CA before trusting it\nctx = trusted_context('/etc/ssl/internal-ca.pem')","typeGuard":"null","tryCatchPattern":"try:\n    resp = await session.get(url)\nexcept aiohttp.ClientConnectorCertificateError as exc:\n    log.error('cert failure for %s: %s', exc.host, exc.certificate_error)\n    # surface to operator; do not silently disable verification\n    raise","preventionTips":["Install private/internal CAs into the trust store or SSLContext used by the connector.","Keep the system clock synced via NTP so validity windows are correct.","Never use ssl=False to bypass certificate errors in production code."],"tags":["ssl","certificate","connection","client-connector"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}