Cloudflare 525 vs 526: SSL Handshake Failed vs Invalid SSL Certificate
Both are TLS problems between Cloudflare and your origin. 525 means TLS couldn’t even be negotiated; 526 means it was negotiated but the certificate failed validation in Full (strict) mode.
525
Cloudflare Error 525: SSL Handshake Failed
Cloudflare couldn’t complete a TLS handshake with your origin (SSL mode Full / Full strict).
Causes & fixes →
526
Cloudflare Error 526: Invalid SSL Certificate
With SSL mode Full (strict), the origin’s certificate is expired, self-signed, or doesn’t match the hostname.
Causes & fixes →| 525 | 526 | |
|---|---|---|
| Handshake | Failed | Succeeded |
| Certificate | Missing / not served | Expired, self-signed or wrong hostname |
| SSL mode | Full or Full (strict) | Full (strict) only |
| Fix | Configure TLS on the origin | Renew/replace the certificate |
Rule of thumb
525 → is TLS set up at all on the origin? 526 → is the certificate valid for this hostname today?