Shared pooler certificate chain fails strict TLS verification: intermediate CA missing Key Usage
The Supabase hosted shared transaction pooler at aws-1-eu-west-2.pooler.supabase.com:6543 presents a certificate chain where the intermediate CA ('Supabase Intermediate 2021 CA') lacks a Key Usage extension. Python 3.13 enables VERIFY_X509_STRICT by default in ssl.create_default_context(), causing certificate verification to fail with error 92 at depth 1. This prevents database connections using asyncpg 0.31.0 and OpenSSL 3.6.3, even when the correct root CA is trusted. The issue is reproducible without credentials and occurs before authentication.
