Cloudflare error 526: invalid SSL certificate

Full (strict) mode rejected your origin's certificate: expired, self-signed, wrong name or missing chain. How to check it and fix it properly.

· 3 min read · By the Spot Downtime team

Error 526: Invalid SSL certificate means Cloudflare connected to your origin over HTTPS, looked at its certificate, and refused to trust it. You only get it in Full (strict) mode, which is the one doing its job: it checks your origin's certificate the way a browser would.

What makes the certificate invalid

It expired

Visitors don't see your origin certificate, Cloudflare's edge certificate is what they get, so an expired origin certificate can go unnoticed until strict mode rejects it. Renewal jobs on origins behind Cloudflare fail quietly more often than you'd think.

It's self-signed

Fine for Full mode, rejected by Full (strict).

It doesn't cover the hostname

The certificate is for example.com but the request is for www.example.com or app.example.com. Check the names it lists.

The chain is incomplete

The server sends only its own certificate without the intermediate. Use the full chain file (for Let's Encrypt, fullchain.pem, not cert.pem).

Check the origin's certificate

bash
openssl s_client -connect 203.0.113.10:443 -servername example.com </dev/null 2>/dev/null \
  | openssl x509 -noout -subject -issuer -dates -ext subjectAltName
SSL certificate checkerSee any certificate's issuer, expiry date, covered names and whether it's trusted.

How to fix it

Pick one:

Install a Cloudflare Origin CA certificate. Free, long-lived, and trusted by Cloudflare in strict mode. The simplest option when all traffic goes through Cloudflare.

Use a publicly trusted certificate such as Let's Encrypt, with automatic renewal, and the full chain configured.

Don't fix it by switching to Full or Flexible

Downgrading the SSL mode makes the error disappear by no longer checking the certificate. Your traffic from Cloudflare to the origin is then open to interception. Fix the certificate instead.

The best fix is not finding out from a 526. Read why certificates still expire, and consider monitoring the origin directly: Spot Downtime warns you 14 days before a certificate it checks expires.

Keep reading