TL;DR: Your Python does not trust the server's certificate chain, usually because certifi is outdated or missing. Run pip install -U certifi; if you use a self-hosted cert, pass tlsCAFile pointing at your CA bundle.

```text
pymongo.errors.ServerSelectionTimeoutError: [host]:27017: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate
```

## Fix it

1. Upgrade the CA bundle: pip install -U certifi. Expected: newest certifi.
2. Retry the connection. Expected: connects. This fixes the majority of Atlas cases.
3. Self-hosted with a private CA: pass tlsCAFile='/path/to/ca.pem' in MongoClient. Expected: verification passes against your CA.
4. Verify quickly: python -c "import certifi; print(certifi.where())" then check the file exists. Expected: a real path.

## When this applies
- ServerSelectionTimeoutError with CERTIFICATE_VERIFY_FAILED in the reason.

## When it doesn't
- Plain timeout with connection refused: the server is unreachable, different fix.
- bad auth errors: TLS is fine; credentials are wrong.

## Compatibility
- pymongo 3.x/4.x; certifi any recent.

## Why it happens
pymongo verifies TLS by default against certifi's CA bundle. Stale bundles (old Docker base images, old certifi pins) do not include current intermediates, so verification fails.

## Edge cases
- Do not set tlsAllowInvalidCertificates=True to silence this in production; it disables all verification.
- Corporate TLS-intercepting proxies need their root CA added to the bundle or via tlsCAFile.
