SSL Handshake Failed: Causes and Fixes (Including 525)

An SSL handshake failure means the browser and server couldn't agree on a secure connection. Find the cause — certificate, protocol, SNI, or CDN — and fix it.

Before a single byte of your page is sent over HTTPS, the browser and the server hold a short negotiation called the TLS handshake. They agree on a protocol version, pick a cipher, and the server proves who it is with its certificate. “SSL handshake failed” means that conversation broke down, so no secure connection exists and no page can be delivered.

You will see it as SSL handshake failed, Secure Connection Failed in Firefox, ERR_SSL_PROTOCOL_ERROR or ERR_SSL_VERSION_OR_CIPHER_MISMATCH in Chrome, SSL_ERROR_HANDSHAKE_FAILURE_ALERT in logs, or — behind Cloudflare — Error 525: SSL handshake failed. The wording varies; the failure is the same. (The label says SSL, but every modern connection actually uses its successor, TLS.)

Who is failing to shake hands?

Figure out which two machines were negotiating. It narrows the causes immediately.

  • Every visitor, in every browser. The server’s certificate or TLS configuration is broken. This is the site owner’s problem.
  • Only you, or only one device. Your clock, your antivirus, a corporate proxy, or an old operating system. See the visitor section below.
  • Cloudflare error 525. The failure is between Cloudflare and your origin server, not between the visitor and Cloudflare. The visitor’s browser is fine.
  • Only a script, API client, or curl. The client’s CA bundle or TLS library is out of date.

Run the domain through the SSL certificate checker. It performs the handshake from an independent server and reports whether the certificate chain is valid, trusted, unexpired, and issued for the hostname. If it passes and your browser fails, look at your own machine first.

Server-side causes

Symptom Likely cause Fix
Fails for everyone since a specific date Certificate expired Renew and reload the server
Fails on one hostname, works on another Certificate does not cover that name, or SNI misrouted Reissue with all names; check virtual host config
Works in Chrome, fails in older clients or curl Incomplete certificate chain Serve the full chain including intermediates
ERR_SSL_VERSION_OR_CIPHER_MISMATCH No protocol or cipher in common Enable TLS 1.2 and 1.3 with modern ciphers
Cloudflare 525 Origin has no valid certificate, or refuses Cloudflare’s handshake Install an origin certificate and match SSL mode
Fails right after a server move Port 443 not listening, or the wrong certificate on the new host Check the listener and the installed certificate

The certificate has expired or is not trusted

An expired certificate is the most common handshake failure of all, and the easiest to prevent. Browsers usually show a specific warning for it — the certificate has expired — but many clients and proxies just report a failed handshake. Self-signed certificates, or certificates from an internal CA, fail the same way for anyone who does not trust that CA.

Fix: renew or replace the certificate with one from a public CA, then reload the web server so it picks up the new files. Renewals that “succeed” but are never loaded by the server are a classic cause of certificates expiring without warning.

The chain is incomplete

Your server must send its own certificate and the intermediate certificates that link it to a trusted root. Desktop browsers often paper over a missing intermediate by fetching or caching it, so the site looks fine to you — while phones, API clients, curl, and crawlers fail the handshake.

Fix: configure the server to send the full chain file (fullchain.pem from Certbot, not cert.pem). In nginx, ssl_certificate should point at the full chain.

The hostname does not match

If the certificate covers example.com but the visitor asked for www.example.com, or a subdomain was added later without reissuing the certificate, validation fails. On servers hosting several sites, a missing or wrong server_name can cause the default site’s certificate to be presented for every hostname — Server Name Indication (SNI) routing gone wrong.

Fix: reissue the certificate with every hostname you serve, and make sure each virtual host names its own certificate.

Protocol or cipher mismatch

Old servers that only offer TLS 1.0 or 1.1 are rejected by every modern browser. The opposite happens too: a hardened server offering only TLS 1.3 will fail with old Android devices, legacy payment terminals, and some monitoring and API clients.

Fix: enable TLS 1.2 and TLS 1.3, and use a maintained cipher list rather than a hand-edited one. Mozilla’s SSL Configuration Generator produces a correct block for nginx, Apache, and most load balancers.

Cloudflare error 525

A 525 means Cloudflare reached your origin server but could not complete a TLS handshake with it. The visitor’s connection to Cloudflare is fine; the second leg is broken.

Common reasons:

  1. SSL mode is Full or Full (strict), but the origin has no certificate or is not listening on port 443.
  2. The origin certificate is expired or self-signed while the mode is Full (strict), which requires a trusted, valid certificate.
  3. The origin firewall drops Cloudflare’s IP ranges on port 443.
  4. The origin supports only protocols or ciphers Cloudflare does not accept.

Fix: install a certificate on the origin — a free Cloudflare Origin CA certificate works for Full (strict) — make sure port 443 is open to Cloudflare, and confirm with openssl s_client -connect ORIGIN_IP:443 -servername example.com. Do not “fix” a 525 by switching to Flexible; that swaps a handshake failure for an unencrypted origin connection and often a redirect loop.

If you are a visitor

  1. Check your device’s date and time. A clock that is wrong by days makes every certificate look invalid.
  2. Disable HTTPS scanning in your antivirus (Avast, Kaspersky, ESET, and others intercept TLS), then retry.
  3. Try another network. Corporate proxies and school filters often break handshakes to specific sites.
  4. Update your browser and operating system. Very old systems lack current root certificates and TLS versions.
  5. If every HTTPS site fails, not just one, see certificate errors on all websites.

How to confirm the fix

  • openssl s_client -connect example.com:443 -servername example.com should end with Verify return code: 0 (ok).
  • Test from a phone on mobile data, not just your desktop browser, to catch chain problems desktops hide.
  • Re-run the SSL checker and note the expiry date it reports.

Stop it happening again

Most handshake failures are certificate lifecycle failures: an expiry nobody saw coming, a renewal that was not reloaded, a chain that broke during a move. SitesRadar’s free plan checks one site’s certificate on a schedule — expiry, trust, chain, and hostname — and emails you well before it becomes an outage, alongside uptime, DNS, and broken links. See SSL certificate expiration monitoring for how to set up renewal alerts properly.

FAQ

What does SSL handshake failed mean? The browser (or other client) and the server could not agree on a secure connection — usually because the certificate is invalid, the chain is incomplete, or they share no common TLS version or cipher.

Is an SSL handshake failure my fault or the website’s? If every browser and device fails, it is the website. If only your device fails, check your clock, antivirus, network, and software versions.

What is Cloudflare error 525? Cloudflare could not complete the handshake with your origin server. Install a valid certificate on the origin, open port 443 to Cloudflare, and match the SSL/TLS mode to what the origin supports.

Can an expired certificate cause a handshake failure? Yes. It is the most common cause. Browsers usually show a specific expiry warning, but many other clients report a generic handshake failure.

How do I test the SSL handshake? Run openssl s_client -connect example.com:443 -servername example.com, or use an independent SSL checker that reports the chain, expiry, and hostname match.

← More from the SitesRadar blog