SSL Error 525 with Network Solutions SSL Certificate

What is the name of the domain?

What is the error number?

SSL Handshake error 525

What is the error message?

SSL Handshake error 525

What is the issue you’re encountering

Intermittent SSL Handshake Error 525

What steps have you taken to resolve the issue?

Confirmed with Network Solutions their SSL certificate is correctly installed. Paused CF and used Qualsys Labs to verify cipher set used by NS cert. and then selected the same cipher set at CF SSL/TSL dashboard. Changed mode to “Full” only. Double checked at all DNS settings are correct at CF and that all 3 DNS entries are proxied. Checked the site multiple times while CF was paused to ensure it’s working and SSL is being served. Then un-paused CF and tried again. Sometimes it works and sometimes it doesn’t. NS is saying their SSL (and NOT CF’s SSL) certificate should propagate and that’s is the error is occuring. Sounds unusual to me and the existing setup was working fine for 4+ years; error 525 only started about 1.5 week ago.

What are the steps to reproduce the issue?

I have not un-paused CF. Just visit the site and click through different links. If error 525 doesn’t come up right away, re-freshing and/or clicking around will either make it appear or make it work. So unusual. Anyone have any ideas what’s wrong or what settings I can change at CF to correct this?

Sorry, typo. I meant to say “I have now un-paused CF.”

Hello,

Error 525 indicates SSL handshake between Cloudflare and the origin web server failed.

The Error 525 occurs when these two conditions are true:

As for the resolution, Contact your hosting provider to exclude the following common causes at your origin web server:

  • No valid SSL certificate is installed.
  • Port 443 (or another custom secure port) is not open.
  • No SNI support.
  • The cipher suites used by Cloudflare do not match the cipher suites supported by the origin web server.

For further information, kindly review this document : Troubleshooting Cloudflare 5XX errors · Cloudflare Support docs

Thank you !

We generated an Origin Certificate at Cloudflare using a “CSR” file Network Solutions generated for us. We then gave the PEM file back to Network Solutions to install onto the server they use hosting our site. However, Network Solutions keep saying they can’t install it, because 1) “there’s no intermediate certs they were expecting”, or that 2) “the CF cert. is not activated”. Can someone help me figure what they are saying and how to correct this? Thanks.

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.