🔶

Cloudflare Error

Cloudflare Error 525: SSL Handshake Failed

Cloudflare could not complete an SSL/TLS handshake with your origin server.

What This Error Means

A 525 means Cloudflare successfully connected to the origin at the TCP level but the SSL/TLS negotiation itself failed — the certificate presented, the cipher suites supported, or the TLS version offered by the origin didn't satisfy what Cloudflare's edge requires or expects for a secure connection.

Why It Occurs

This happens when the origin's SSL certificate is expired, self-signed (and Cloudflare's SSL mode requires a valid cert), or when the origin only supports outdated/deprecated TLS versions or cipher suites that Cloudflare's edge won't negotiate with for security reasons.

Symptoms

  • ⚠ Error 525 shown for all requests, consistently
  • ⚠ Site works fine when Cloudflare proxying is temporarily disabled (grey-clouded)

Common Causes

  • • The origin's SSL certificate has expired
  • • Cloudflare's SSL/TLS mode is set to "Full (strict)" but the origin uses a self-signed or invalid certificate
  • • The origin only supports an outdated TLS version (TLS 1.0/1.1) that Cloudflare no longer negotiates by default
  • • A mismatch between the certificate's domain and the hostname being requested

How to Fix It

  1. Check the origin's certificate expiry: `openssl s_client -connect origin-ip:443 -servername yourdomain.com </dev/null 2>/dev/null | openssl x509 -noout -dates`
  2. If the certificate is expired or self-signed, either install a valid certificate on the origin (Let's Encrypt is free) or change Cloudflare's SSL/TLS mode to "Full" (not strict) temporarily — understanding this reduces validation, not a permanent recommended fix
  3. Confirm the origin supports TLS 1.2 or higher: check the web server's TLS configuration (Nginx `ssl_protocols` directive, or equivalent)
  4. Confirm the certificate's Common Name/Subject Alternative Names actually match the domain being requested
CommandPurpose
openssl s_client -connect origin-ip:443 -servername yourdomain.comInspect the certificate the origin actually presents
Advertisement

Verification

  • ✓ Re-run the openssl command and confirm a valid, non-expired certificate is presented
  • ✓ Confirm the site loads correctly with Cloudflare's SSL mode set to "Full (strict)"

Prevention

  • → Automate certificate renewal (certbot with a cron job/systemd timer) so certificates never silently expire
  • → Use Cloudflare's Origin CA certificates specifically designed for the Cloudflare-to-origin connection, which are trusted automatically under Full (strict) mode

Related