ERR_SSL_PROTOCOL_ERROR and ERR_SSL_VERSION_OR_CIPHER_MISMATCH explained

When HTTPS can't be set up at all: plain HTTP on port 443, outdated TLS versions and missing edge certificates, and how to test the handshake.

· 4 min read · By the Spot Downtime team

Two Chrome errors mean the secure connection couldn't even be set up: ERR_SSL_PROTOCOL_ERROR (“This site can't provide a secure connection”) and ERR_SSL_VERSION_OR_CIPHER_MISMATCH (“uses an unsupported protocol”). Unlike certificate errors, there's no “proceed anyway”: the browser and server never agreed on how to talk.

ERR_SSL_PROTOCOL_ERROR

Something answered on the HTTPS port, but not with a valid TLS handshake.

Plain HTTP on port 443

The server listens on 443 without SSL enabled, so it replies to the TLS hello with plain HTTP. In nginx, the listen line is missing ssl:

nginx
listen 443 ssl;          # not just: listen 443;
http2 on;

No certificate configured for this name

Some servers abort the handshake when they have no certificate for the requested hostname, instead of falling back to another one.

Something in the middle

A proxy, firewall or antivirus that interferes with TLS. If many sites fail on one network, it's the network.

ERR_SSL_VERSION_OR_CIPHER_MISMATCH

The handshake started, but there was no protocol version or cipher both sides support.

  • An outdated server that only supports TLS 1.0 or 1.1, which modern browsers have dropped. Enable TLS 1.2 and 1.3.
  • Cloudflare without an edge certificate for this hostname. Universal SSL covers example.com and *.example.com, but not deeper names like a.b.example.com. A brand-new domain can also show this briefly while the certificate is issued.
  • An RC4 or other obsolete cipher list copied from an old guide.
nginx
ssl_protocols TLSv1.2 TLSv1.3;

Test the handshake

bash
openssl s_client -connect example.com:443 -servername example.com -tls1_2 </dev/null
openssl s_client -connect example.com:443 -servername example.com -tls1_3 </dev/null
# "wrong version number" = the server isn't speaking TLS on this port
# "no protocols available" / "handshake failure" = no common version or cipher
SSL certificate checkerCheck whether a site completes the HTTPS handshake and serves a valid certificate.Security headers gradeOnce HTTPS works, grade the site's HTTPS setup and security headers, with what to fix.

For visitors

Check your device's date and time, update your browser, and try without VPN or antivirus HTTPS scanning. On very old devices, modern sites may simply be unreachable.

Handshake failures make every HTTPS request fail, so a website monitor catches them on the first check. Related: Cloudflare error 525 is the same failure between Cloudflare and your server.

Keep reading