Community Tip - Fixing Error 525: SSL handshake failed

Error
Try the suggestions in this Community Tip to help you fix Error 525: SSL handshake failed.

Background
Error 525 indicates that the SSL handshake between Cloudflare and the origin web server failed. This only occurs when the domain is using Cloudflare Full or Full (Strict) SSL mode. This is typically caused by a configuration issue in the origin web server, when this happens, you’ll see “Error 525: SSL handshake failed”.

Dedicated SSL

Quick Fix Ideas

  1. If you are a site visitor, report the problem to the site owner. Neither this Community nor Cloudflare Support can assist you. Cloudflare Support only works with the verified owner of the domain.

  2. Make sure you have a valid SSL certificate installed on your origin server.

  • To display your origin certificate, replace 203.0.113.34 with the origin IP address of your web server & replace www.example.com with your domain and host name:

$ curl -svo /dev/null https://www.example.com --connect-to ::203.0.113.34 2>&1 | egrep -v "^{.*$|^}.*$|^* http.*$"

  1. Check with your hosting provider to make sure they’re listening on port 443/whatever other port you are using.

  2. Check to make sure your origin server is properly configured for SNI.

  3. The cipher suites that Cloudflare accepts and the cipher suites that the origin server supports do not match. Review the cipher suites your server is using to ensure they match what is supported by Cloudflare. A cipher suite is a set of algorithms that help secure a network connection that uses Transport Layer Security (TLS) or its now-deprecated predecessor Secure Socket Layer (SSL). The set of algorithms that cipher suites usually include: a key exchange algorithm, a bulk encryption algorithm, and a message authentication code (MAC) algorithm.

  4. If you are the site owner and you’re only seeing errors intermittently, this suggests the TCP connection between Cloudflare and your origin is being reset during the SSL handshake causing the error. Ask your hosting provider/system administrator to check if there are any server issues. Reviewing your webserver access/error logs would be a good place to locate this information.

  5. Note that Apache must be configured to log mod_ssl errors and nginx includes these errors in its standard error log, but it may be necessary to increase the log level.

  6. Pause Cloudflare or update your local hosts file to point directly at your server IP to test that your server is presenting a SSL certificate. If you do not have a certificate installed on your server you can generate one using our Origin CA certificates. This is a free certificate for the purpose of encrypting the connection between Cloudflare and your web server, so that you do not need to purchase a certificate.

  7. If you cURL to the origin on port 443 and receive the error error:1408F10B:SSL routines:ssl3_get_record:wrong version number, disable TLS 1.3 on the Edge Certificates tab of the SSL/TLS app on the Cloudflare dashboard. To determine what TLS version is currently supported, use the following cURL command, replace MYORIGINIP with the IP address shown on the A record of your DNS app in the Cloudflare dashboard and www.example.com with your domain:
    $ curl -svo /dev/null https://www.example.com --connect-to ::MYORIGINIP 2>&1 | egrep -v "^{.*$|^}.*$|^* http.*$"
    Test a specific TLS version by adding one of the following options to your cURL:

  • –tlsv1.0
  • –tlsv1.1
  • –tlsv1.2
  • –tlsv1.3

Lite Reading
https://support.cloudflare.com/hc/en-us/articles/115003011431#525error

Community Tutorial

Learning Center
What Is SSL? | SSL and TLS

Background Resources
Help Center
YouTube

Research The Issue
Community
Google

Security Option
Dedicated SSL Certificates allow you to secure multiple levels of your subdomains and include your fully qualified domain name in the Common Name (CN). Learn more about Dedicated SSL Certificates.

If You Need More Help
This community of other Cloudflare users may be able to assist you, login to Cloudflare and post your question to the Community. When you post on the Community make sure to include as much of this information as possible: the specific error message you are seeing, the URLs this is happening on, screen shot of the error, and the steps to reproduce the error. Please indicate what troubleshooting steps you’ve tried in order to help us help you.

This is a Cloudflare Community Tip, to review other tips click here.

Çevirme…traduzir…翻译…traducir…Traduire…Übersetzen…:greyg: Translate this Tip

FXHFCT 103119

3 Likes
525 error - called Godaddy and was told the issue is with Cloudflare
Ssl handshake faild
# Error 525 <small>Ray ID: 514731ee394ec410 • 2019-09-11 05:20:53 UTC</small> ## SSL handshake failed
Ssl not working for my subdomains
My website is not showing
CloudFlare SSL Handshake (525)
SSL Problems Handshake Error, Activate Certificates?
Unusual 525 error with website
How to configure a port in cloudflare
525 error SSL handshake
SSL HandShake Failed | Error 525
SSL Error 525 with Rails and Heroku
Apologies if same issue reported - Godaddy error 525
Cloudflare problem urgents please
SSL Handshake Failed (cgpproducts.com)
I am getting 525 handshake error and when I did a search on whynopadloack.com every thing is alright
Help Known Issues
Ssl handsake failed
Error 525 SSL Handshake With LightCMS Failed
I can't open my website after using CF
I think that my cloud not working at all
Getting Error 525 even though no changes were made
DNS and Blogspot custom domain
Secure connection failed
How to fix Error 525 SSL handshake failed
Error 525 with ovh
SSL 525 error
ERROR 525 / SSL handshake failed
Error 525 - SSL Handshake Fail + Spike in Traffic
Get error 525
Website not working Error 525
Error 525 I can't access my page
Error 525 SSL failed
Text boxes of payment gateway plugin inactive
Community Tip - Helpful Links, on Display
SSL Handshake Error?
525 SSL Handshake Errors
WebSocket issue WSS
Randomly getting Error 525 each day or each few days
Connection to this is not secure?
Randomly getting Error 525 each day or each few days
Error 526 Invalid SSL certificate (running nginx)
Intermittent 525 and 503 errors
Subdomínio
Getting 525 error for my site
SSL handshake failed - Error 525
525 SSL handshake failure
DNS record seem to not being propagated properly
Cloudflare/HaProxy - Error 525 - SSL Handshake Failed
I have problem with payment system and show this problem
Authenticated Origin Pulls - Handshake failed
Just Too much Issues In Free Services
Emergency - site is down
This site can’t be reached hetmoederbedrijf.com
Ssl handshake fail
Error 525 SSL handshake failed after activation
My site is still 'not secure'
Ubuntu 18 on AWS using Nginx and Cloudflare
Errors 525/522 but only to my IP
SSL Certificate isn't getting recognised Full (Strict)
Intermittent 525 SSL
High latency through Cloudflare proxy in Canada
Error 525 Ray ID: 57c47a461f5c73d1 • 2020-03-30 20:11:26 UTC SSL handshake failed
I created a Cloudflare account... How do I add my hosting to it?
Error 520/525/502
Visibility
Error 525 Showing on my Website
Help error 525 y 520
Ahmadimado.net/dashboard
I am facing 525 ssl handshake failed error
I always take Error 525
Help With ERR_TOO_MANY_REDIRECTS
Unsupported SSL Certificate issue
Https not working Error 525
There are always errors on my website 503 and error 525 errors
525 error under selenium webdriver test (ruby capybara)
It appears that the SSL configuration used is not compatible with Cloudflare
SSL And HTTPS Not Working
IP address of cloudflare server when displaying error message
No "Free" with SSL
Status 521
525 Errors happens regularly today on http call for resources
My StoreEnvy customer site down with a 525 error
Error 525 SSL handshake failed blogger
525 Errors happens regularly today on http call for resources
Https error 525
Redirecionar para ip diferente via registro A / AAAA com subdominio
Website not working on http to https
SSL handshake failed!
Error 525 - need clarification
I paused cloudflare for my site, will APO also be paused? Or APO will run seperately?
Not getting SSL Cert
Subdomain 525 Error
Website speed is not inscreing
Host error
Domain is not working - Shows an Error!
SSL Full encryption not working
525 error despite SSL strict mode not enabled
Purecareers.in
Google admin
SSL Handshake failed with my subdomain
How to solve Error 525?
Error 525 (SSL handshake failed)
Ssl handshake error on subdomains
Run 2 scheduled workers within 5 seconds of each other
525 Handshake error blogger + cloudflare + godaddy domain
"www" subdomain not working for my website
How to fix issue "Error 525: SSL handshake failed"
Universal SSL not turning on
Error 525 while accessing website vmcloudguru.com
Istanbul cloudflare errors 525 but frankfurt doesn't
Error 521 (10 chars)
Fixing Errors 521 and 525! (Tutorial)
The Speed test can’t run
GTmetrix and 500 message caused by cloudflare - how do I fix?
SSL handshake failed/Error 525
Initial set up and Error 525 - SSL Handshake failed
Some of your DNS only records are exposing IPs that are proxied through Cloudflare. Make sure to proxy all A, AAAA, and CNAME records pointing to proxied records to avoid exposing your origin IP
SSL handshake 525 error
## SSL handshake failed & Host Error
ERROR 525 - HOST error
Two website to one server
Site stopped working on full/strict setting but works on flexible
SSL handshake failed 525
How can I resolve a 525 error for my glide app on a subdomain of my website?
Error 525 • 2020-12-12 02:42:28 UTC SSL handshake failed
Error 520. Web server is returning an unknown error
Stick in ssl errors
Https://egytv.ml/
Is Cloudflare throttling our county's Covid Vaccine appointment website?
Webflow Steup
Community Tip - Alle veröffentlichten Tipps
Community Tip - Sicherheits-FAQ
No redirect or SSL on subdomain
Error 525 Hand shake failed between cloudflair and domain
Not accepting the operation of my site
Community Tip - 公開されているすべてのヒント
CommunityTip - セキュリティに関するFAQ最初にお読みくださ
525 errors on site, registration unknown
SSl Error facing
Error 525 I can't access my page
SSL not working on desktop
Hello, I need Emergency help here
CommunityTip - Security FAQ Read Me First
SSL/TLS Flexible and Full setting not working
I can't access my site
Error 525 Problemm
Error 505 SSL handshake failed
Problems with redirects
SSL handshake failed with Nginx ubantu 10.0
Web server changed. 525 error
SSL Certificate?
Error 525 and Error 520
Сменил DNS у регистратора доменов но сайт не заработал
Cloudflare active website is not available
Help, site is not working, please help
520 Error with WordPress Divi Builder
DNS & Network
Unstable service
How many 525 errors am I getting?
Cant able to fix Error 525
Gmail mail.*yourwebsite*.com no longer works with cloudflare
Cant set up Port
DNS will not resolve to IPv4
Need Help Setting up Strict SSL
Community Tip - All Published Tips
Ssl error subdomain
My Website is down after changing to CloudFlare Nameservers
More than 50% 525 Errors - Need technical help
Website looking like raw HTML
Issues pointing my domain in Cloudflare to my Google Site (new google sites)
More than 50% 525 Errors - Need technical help
From error 525 to Red https is this progress?
Error 525! Please help
Intermittent 525 SSL Handshake Error