ERR_SSL_VERSION_OR_CIPHER_MISMATCH
I have let’s encrypt ssl active on my host. Later I have transferred DNS to cloud fare and uninstalled let’s encrypt ssl.
And now my site is showing: ERR_SSL_VERSION_OR_CIPHER_MISMATCH
And in Cloudfare DNS record, CAA showed DNS only in proxy status.
For past 30 hours, I am unable to open my site.
Can anyone help???
sandro
December 31, 2021, 10:13am
#2
Sorry, that’s a mistake. Re-install that a quickly as possible, otherwise your site is insecure. That’s also why you have that error.
Cloudfare has universal ssl for free plan, won’t it interfere if…ssl at my host is active.
sandro
December 31, 2021, 11:48am
#4
No, the Cloudflare certificate is only for the proxies and if you don’t have a certifcate on your server you obviously can’t have a secure connection.
The certificate on your server needs to be in place. You could only replace it with an Origin certificate if you want, but you still need one there.
Thank you…but to activate ssl at my host, I have to first point dns to my host aand activate ssl and then later change dns to cloud fare.
Is there another way??
sandro
December 31, 2021, 11:52am
#6
In that case you might want to go that route
Origin certificate is it under business plan??
sandro
December 31, 2021, 11:55am
#8
Origin certificates can be issued on all plans. It’s a few clicks and you have a proper certificate for Cloudflare.
Thank you for your help!!!
sandro
December 31, 2021, 11:57am
#10
No worries.
Why you should choose Full Strict, and only Full Strict has all details on that, also how to get the certificate.
I have added origin certificate from cloudfare to my host, and ssl is enabled showing there but still
No SSL certificates were found on beautybrute.com . Make sure that the name resolves to the correct server and that the SSL port (default is 443) is open on your server’s firewall.
Message shown on sslshopper.com
And I am unable to open my site due to ERR_SSL_VERSION_OR_CIPHER_MISMATCH
( Unsupported protocol - The client and server don’t support a common SSL protocol version or cipher suite.)
What should I do??
sdayman
December 31, 2021, 2:02pm
#12
Check the Edge Certificates section under SSL/TLS. You should see an Active certificate.
Error
Try the suggestions in this Community Tip for best practices in certificate provisioning.
Background
SSL certificates can often be issued in 10-15 minutes. If you are using free Universal SSL, it can take up to 24 hours. Please do not reach out for support until it has been “authorizing” for more than a day. Before contacting support, you may be able to successfully trouble shoot the issue with some of these Quick Fix Ideas.
[Dedicated SSL]
Quick Fix Ideas
If you are using a CNAME …
sandro
December 31, 2021, 2:44pm
#13
That would indicate Cloudflare has not provisioned the proxy certificate yet.
Check https://dash.cloudflare.com/?to=/:account/:zone/ssl-tls/edge-certificates for that and possibly disable Universal SSL for an hour and then re-enable it.
1 Like
sandro
December 31, 2021, 3:15pm
#15
Appears to have worked. Now just make sure your encryption mode is Full Strict and you are all set
Yes…it worked and I have changed ssl to strict mode.
Thank you for your help!!!
system
closed
January 3, 2022, 5:04pm
#17
This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.