Ssl version cipher mismatch / sslv3 alert handshake failure

Hi folks,

Here is the problem which drives me nuts for several hours now :

In order to have a testing / pre-production environment online we have cloned the production one on another machine.

Everything is absolutely the same on “preprod” and “prod” side. Just everything.
The production side is fine, the preprod one is not and answering with ERR_SSL_VERSION_OR_CIPHER_MISMATCH (on browser) and sslv3 alert handshake failure (with curl / wget)

Everything is fine with the production environment (which run fine for several months) so there is nothing to do with CF config : certs are fine, configuration is fine everything works… but not on preprod.

The stack is nginx with the same certs on both environments : do we have to create another cert for preprod environment ?

For reference :

  • production endpoint (which works) : api dot jobs-meetings dot com
  • preprod endpoint (faulty) : preprod dot api dot jobs-meetings dot com

Thanks for you help!


Thank you for asking.

If you’d want to use it over a proxied :orange:, you’d have to use Advanced Certificate Manager, since it’s a deep-level sub-domain and Cloudflare’s Universal SSL cover only 1st level sub-domain:

Otherwise, if you’re already using ACM, is the SSL certificate still a valid one at the origin host? :thinking:

OMG ok… tkanks

