Cloudflare Error
Cloudflare Error 526: Invalid SSL Certificate
Cloudflare completed the SSL handshake but the origin's certificate failed validation under "Full (strict)" mode.
What This Error Means
A 526 is more specific than a 525: the handshake itself completed, but Cloudflare — running in "Full (strict)" SSL mode — could not validate the origin's certificate against a trusted certificate authority. This is Cloudflare's strictest SSL mode specifically refusing to trust an untrusted or invalid certificate on your behalf.
Why It Occurs
The origin is presenting a self-signed certificate, an expired certificate, or a certificate whose chain doesn't include a trusted intermediate/root CA, while Cloudflare's SSL/TLS mode is set to "Full (strict)", which requires full validation.
Symptoms
- ⚠ Error 526 shown consistently for all requests
- ⚠ Certificate looks fine in a normal browser test directly against the origin, but Cloudflare specifically rejects it
Common Causes
- • Origin uses a self-signed certificate with Full (strict) mode enabled
- • Origin's certificate chain is missing the intermediate certificate
- • Origin's certificate has expired
How to Fix It
- Install a properly chain-complete, CA-signed certificate on the origin (Let's Encrypt via certbot is free and automatable)
- Alternatively, use a Cloudflare Origin CA certificate — generated directly in the Cloudflare dashboard specifically for the origin, and automatically trusted under Full (strict)
- Verify the full chain is being served, not just the leaf certificate: `openssl s_client -connect origin-ip:443 -servername yourdomain.com -showcerts`
| Command | Purpose |
|---|---|
| openssl s_client -connect origin-ip:443 -showcerts | Inspect the full certificate chain the origin presents |
Verification
- ✓ Re-check the certificate chain is complete and CA-signed, or confirm a Cloudflare Origin CA cert is correctly installed
- ✓ Confirm the site loads under Full (strict) mode without error
Prevention
- → Use Cloudflare Origin CA certificates specifically for the Cloudflare-to-origin leg, since they're designed exactly for this validation mode
- → Monitor certificate expiry proactively rather than discovering it via an outage