Tell HN: Python 3.6 on OS X requires a post-install step for SSL to work
To fix this you need to run a command [0] included in the installer that will download and install the certifi package, which is a collection of trusted certificates. If I understand the release notes correctly you are also now responsible for making sure your certificates are up to date - the release notes recommend subscribing to the mailing list.
Personally, I think this sucks. It makes Python way less friendly to new users, and I don't want to be on the hook for keeping my certificates up-to-date. At the very least, the installer should run the post-install script automatically, so that SSL connections just work.
The ReadMe with more info lives at /Applications/Python\ 3.6/ReadMe.rtf
[0] /Applications/Python\ 3.6/Install\ Certificates.command