HTTP 5xx

525 SSL Handshake Failed

A Cloudflare-specific code: the TLS handshake between Cloudflare and your origin failed.

5xx Server errorCommonly seen

What causes it

  • The origin has no valid certificate for the Full/Strict SSL mode, a cipher or TLS-version mismatch, or an expired origin certificate.

How to fix it

Install a valid certificate on the origin (a Cloudflare Origin Certificate works), or match the SSL/TLS mode to what the origin supports.

Example response

A typical raw HTTP response a client receives for a 525, with the headers this code is defined around.

HTTP/1.1 525 SSL Handshake Failed
Content-Type: text/html; charset=utf-8

Know before your visitors do.

Sentinel checks your site around the clock from multiple regions and alerts you the moment it starts returning a 5xx error, so you can fix it before it costs you.