ERR_SSL_VERSION_OR_CIPHER_MISMATCH: "This site can't provide a secure connection"

Chrome and your server could not agree on how to encrypt the connection. On a small business site this almost always means there is no certificate for that exact name, not that ciphers are wrong.

What to do, in order

  1. Check which name fails. Try both yoursite.com and www.yoursite.com. Often one works and the other has no certificate. Add the missing name to the certificate.
  2. Just moved to Cloudflare? Cloudflare's free certificate takes up to 24 hours to issue after you switch nameservers. It also only covers one level: shop.yoursite.com is covered, dev.shop.yoursite.com is not.
  3. Just moved hosts? The new host has not issued a certificate yet. In cPanel run AutoSSL; on other hosts look for "SSL" next to the domain and switch it on.
  4. Old server software. If the server only speaks TLS 1.0 or 1.1, modern browsers refuse. Test with openssl s_client -connect yoursite.com:443 -tls1_2. If that fails, ask the host to enable TLS 1.2 and 1.3.
  5. Antivirus on one computer. If only one machine sees it, turn off "HTTPS scanning" in its antivirus and try again.

If none of these fit, send me the address and I will check which names and protocols your server offers.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.