🔶

Cloudflare Error

Cloudflare Error 526: Invalid SSL Certificate

Cloudflare completed the SSL handshake but the origin's certificate failed validation under "Full (strict)" mode.

What This Error Means

A 526 is more specific than a 525: the handshake itself completed, but Cloudflare — running in "Full (strict)" SSL mode — could not validate the origin's certificate against a trusted certificate authority. This is Cloudflare's strictest SSL mode specifically refusing to trust an untrusted or invalid certificate on your behalf.

Why It Occurs

The origin is presenting a self-signed certificate, an expired certificate, or a certificate whose chain doesn't include a trusted intermediate/root CA, while Cloudflare's SSL/TLS mode is set to "Full (strict)", which requires full validation.

Symptoms

  • ⚠ Error 526 shown consistently for all requests
  • ⚠ Certificate looks fine in a normal browser test directly against the origin, but Cloudflare specifically rejects it

Common Causes

  • • Origin uses a self-signed certificate with Full (strict) mode enabled
  • • Origin's certificate chain is missing the intermediate certificate
  • • Origin's certificate has expired

How to Fix It

  1. Install a properly chain-complete, CA-signed certificate on the origin (Let's Encrypt via certbot is free and automatable)
  2. Alternatively, use a Cloudflare Origin CA certificate — generated directly in the Cloudflare dashboard specifically for the origin, and automatically trusted under Full (strict)
  3. Verify the full chain is being served, not just the leaf certificate: `openssl s_client -connect origin-ip:443 -servername yourdomain.com -showcerts`
CommandPurpose
openssl s_client -connect origin-ip:443 -showcertsInspect the full certificate chain the origin presents
Advertisement

Verification

  • ✓ Re-check the certificate chain is complete and CA-signed, or confirm a Cloudflare Origin CA cert is correctly installed
  • ✓ Confirm the site loads under Full (strict) mode without error

Prevention

  • → Use Cloudflare Origin CA certificates specifically for the Cloudflare-to-origin leg, since they're designed exactly for this validation mode
  • → Monitor certificate expiry proactively rather than discovering it via an outage

Related