Cloudflare Error
Cloudflare Error 525: SSL Handshake Failed
Cloudflare could not complete an SSL/TLS handshake with your origin server.
What This Error Means
A 525 means Cloudflare successfully connected to the origin at the TCP level but the SSL/TLS negotiation itself failed — the certificate presented, the cipher suites supported, or the TLS version offered by the origin didn't satisfy what Cloudflare's edge requires or expects for a secure connection.
Why It Occurs
This happens when the origin's SSL certificate is expired, self-signed (and Cloudflare's SSL mode requires a valid cert), or when the origin only supports outdated/deprecated TLS versions or cipher suites that Cloudflare's edge won't negotiate with for security reasons.
Symptoms
- ⚠ Error 525 shown for all requests, consistently
- ⚠ Site works fine when Cloudflare proxying is temporarily disabled (grey-clouded)
Common Causes
- • The origin's SSL certificate has expired
- • Cloudflare's SSL/TLS mode is set to "Full (strict)" but the origin uses a self-signed or invalid certificate
- • The origin only supports an outdated TLS version (TLS 1.0/1.1) that Cloudflare no longer negotiates by default
- • A mismatch between the certificate's domain and the hostname being requested
How to Fix It
- Check the origin's certificate expiry: `openssl s_client -connect origin-ip:443 -servername yourdomain.com </dev/null 2>/dev/null | openssl x509 -noout -dates`
- If the certificate is expired or self-signed, either install a valid certificate on the origin (Let's Encrypt is free) or change Cloudflare's SSL/TLS mode to "Full" (not strict) temporarily — understanding this reduces validation, not a permanent recommended fix
- Confirm the origin supports TLS 1.2 or higher: check the web server's TLS configuration (Nginx `ssl_protocols` directive, or equivalent)
- Confirm the certificate's Common Name/Subject Alternative Names actually match the domain being requested
| Command | Purpose |
|---|---|
| openssl s_client -connect origin-ip:443 -servername yourdomain.com | Inspect the certificate the origin actually presents |
Verification
- ✓ Re-run the openssl command and confirm a valid, non-expired certificate is presented
- ✓ Confirm the site loads correctly with Cloudflare's SSL mode set to "Full (strict)"
Prevention
- → Automate certificate renewal (certbot with a cron job/systemd timer) so certificates never silently expire
- → Use Cloudflare's Origin CA certificates specifically designed for the Cloudflare-to-origin connection, which are trusted automatically under Full (strict) mode