pymongo.errors.ServerSelectionTimeoutError: SSL: CERTIFICATE_VERIFY_FAILED
Fixes pymongo TLS connections failing certificate verification, common with Atlas. Use when the timeout error mentions CERTIFICATE_VERIFY_FAILED. Not for plain connection refused.
TL;DR: Your Python does not trust the server's certificate chain, usually because certifi is outdated or missing. Run pip install -U certifi; if you use a self-hosted cert, pass tlsCAFile pointing at your CA bundle.
pymongo.errors.ServerSelectionTimeoutError: [host]:27017: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificateFix it
- Upgrade the CA bundle: pip install -U certifi. Expected: newest certifi.
- Retry the connection. Expected: connects. This fixes the majority of Atlas cases.
- Self-hosted with a private CA: pass tlsCAFile='/path/to/ca.pem' in MongoClient. Expected: verification passes against your CA.
- Verify quickly: python -c "import certifi; print(certifi.where())" then check the file exists. Expected: a real path.
When this applies
- ServerSelectionTimeoutError with CERTIFICATEVERIFYFAILED in the reason.
When it doesn't
- Plain timeout with connection refused: the server is unreachable, different fix.
- bad auth errors: TLS is fine; credentials are wrong.
Compatibility
- pymongo 3.x/4.x; certifi any recent.
Why it happens
pymongo verifies TLS by default against certifi's CA bundle. Stale bundles (old Docker base images, old certifi pins) do not include current intermediates, so verification fails.
Edge cases
- Do not set tlsAllowInvalidCertificates=True to silence this in production; it disables all verification.
- Corporate TLS-intercepting proxies need their root CA added to the bundle or via tlsCAFile.