ERR_SSL_PROTOCOL_ERROR and ERR_SSL_VERSION_OR_CIPHER_MISMATCH explained
When HTTPS can't be set up at all: plain HTTP on port 443, outdated TLS versions and missing edge certificates, and how to test the handshake.
· 4 min read · By the Spot Downtime team
Two Chrome errors mean the secure connection couldn't even be set up: ERR_SSL_PROTOCOL_ERROR (“This site can't provide a secure connection”) and ERR_SSL_VERSION_OR_CIPHER_MISMATCH (“uses an unsupported protocol”). Unlike certificate errors, there's no “proceed anyway”: the browser and server never agreed on how to talk.
ERR_SSL_PROTOCOL_ERROR
Something answered on the HTTPS port, but not with a valid TLS handshake.
Plain HTTP on port 443
The server listens on 443 without SSL enabled, so it replies to the TLS hello with plain HTTP. In nginx, the listen line is missing ssl:
listen 443 ssl; # not just: listen 443;
http2 on;No certificate configured for this name
Some servers abort the handshake when they have no certificate for the requested hostname, instead of falling back to another one.
Something in the middle
A proxy, firewall or antivirus that interferes with TLS. If many sites fail on one network, it's the network.
ERR_SSL_VERSION_OR_CIPHER_MISMATCH
The handshake started, but there was no protocol version or cipher both sides support.
- An outdated server that only supports TLS 1.0 or 1.1, which modern browsers have dropped. Enable TLS 1.2 and 1.3.
- Cloudflare without an edge certificate for this hostname. Universal SSL covers
example.comand*.example.com, but not deeper names likea.b.example.com. A brand-new domain can also show this briefly while the certificate is issued. - An RC4 or other obsolete cipher list copied from an old guide.
ssl_protocols TLSv1.2 TLSv1.3;Test the handshake
openssl s_client -connect example.com:443 -servername example.com -tls1_2 </dev/null
openssl s_client -connect example.com:443 -servername example.com -tls1_3 </dev/null
# "wrong version number" = the server isn't speaking TLS on this port
# "no protocols available" / "handshake failure" = no common version or cipherFor visitors
Handshake failures make every HTTPS request fail, so a website monitor catches them on the first check. Related: Cloudflare error 525 is the same failure between Cloudflare and your server.
Keep reading
- SSL · Browser errorsNET::ERR_CERT_DATE_INVALID: expired certificate or wrong clock?How to tell whether the certificate expired or the device clock is wrong, how to renew and reload properly, and how to never be surprised by it again.October 5, 2026 · 3 min read
- SSL · Browser errorsNET::ERR_CERT_COMMON_NAME_INVALID: certificate doesn't match the domainThe certificate is for a different name. www vs bare domain, wildcard limits, default certificates and DNS pointing elsewhere.October 5, 2026 · 3 min read