Cloudflare "Error 525: SSL handshake failed"

Cloudflare reached your server but could not agree on a secure connection with it. Your visitors' side is fine. The certificate on your own server is the problem.

What to do, in order

  1. Check the SSL mode. In Cloudflare, go to SSL/TLS. "Full" and "Full (strict)" need a working certificate on your server, on port 443.
  2. Test port 443 directly. Run openssl s_client -connect YOUR.SERVER.IP:443 -servername yourdomain.com. If it fails to connect, the web server is not listening on 443. Enable the SSL site in nginx or Apache.
  3. Check the certificate is current. An expired Let's Encrypt certificate gives 525 or 526. Renew with sudo certbot renew. A free Cloudflare Origin Certificate also works and lasts years.
  4. Check the hostname. The certificate must cover the domain Cloudflare asks for. One issued only for www fails on the bare domain.
  5. Stop the bleeding. Setting the mode to "Flexible" brings the site back at once while you fix the certificate. Switch back to Full afterwards.

If you are stuck, send me the address and I will find the failing step.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.