Since few hours ago SSL connect can’t be establish with CF fron-facing servers:

openssl s_client --connect
4380362112:error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure:ssl/record/rec_layer_s3.c:1544:SSL alert number 40

If I switch to DNS only mode all works fine, otherwise 3rd party checks and openssl test connect do not work, browsers give SSL_ERROR_NO_CYPHER_OVERLAP.

.ru domain by any chance?

Yep! I suggested this in a similar topic below but my response was quickly banned! Thanks you!

So you fixed the issue?

Nope, my free plan doesn’t allow uploading my own cert, will probably have to upgrade

You don’t need to upgrade, you only need to follow the thread I linked.

Try toggling Universal SSL and if that doesn’t fix it, use the API.

Hmm, I saw that advise in the original thread annagolubeva24 .ru, she replied it didn’t help and I now see on this site a new letsencypt cert issued today. Anyway, I just tried turning it off and on - no luck!

Well, in that case you try the alternative way.

Actually, second attempt to turn off/on universal SSL did work, now LE cert is used, thank you!!!

