HTTP 5xx
525 SSL Handshake Failed
A Cloudflare-specific code: the TLS handshake between Cloudflare and your origin failed.
What causes it
- The origin has no valid certificate for the Full/Strict SSL mode, a cipher or TLS-version mismatch, or an expired origin certificate.
How to fix it
Install a valid certificate on the origin (a Cloudflare Origin Certificate works), or match the SSL/TLS mode to what the origin supports.
Example response
A typical raw HTTP response a client receives for a 525, with the headers this code is defined around.
HTTP/1.1 525 SSL Handshake Failed
Content-Type: text/html; charset=utf-8Related codes
500Common
Internal Server ErrorA generic server-side error. Something failed on the server and it could not complete the request.501
Not ImplementedThe server does not support the functionality required to fulfill the request.502Common
Bad GatewayA server acting as a gateway or proxy got an invalid response from the upstream server it was trying to reach.503Common
Service UnavailableThe server is temporarily unable to handle the request, usually because it is overloaded or down for maintenance.504Common
Gateway TimeoutA gateway or proxy did not get a timely response from the upstream server.505
HTTP Version Not SupportedThe server does not support the HTTP protocol version used in the request.Know before your visitors do.
Sentinel checks your site around the clock from multiple regions and alerts you the moment it starts returning a 5xx error, so you can fix it before it costs you.