SSL error: tlsv1 alert protocol version / unsupported protocol / no protocols available
The client and server couldn’t agree on a TLS version or cipher, so the HTTPS handshake failed before any HTTP was exchanged.
Seen on:
REST API
Meaning
Servers now refuse old TLS 1.0/1.1, and some clients (old Java, old OpenSSL, legacy .NET) can’t speak TLS 1.2/1.3 — or the reverse: a modern client refusing a legacy server. OpenSSL reports “tlsv1 alert protocol version” or “unsupported protocol”, Java “No appropriate protocol (protocol is disabled or cipher suites are inappropriate)”, browsers ERR_SSL_VERSION_OR_CIPHER_MISMATCH, curl error 35.
Common causes
- Client limited to TLS 1.0/1.1 (old runtime, explicit setting)
- Server only allows TLS 1.3 / modern ciphers and the client is old
- Java/OpenSSL security policy disables the needed version
- Corporate proxy doing TLS interception with old settings
⚡ Quick fix
- Upgrade the runtime/OpenSSL or enable TLS 1.2+ in the client
- Test which versions the server supports
- Avoid hard-coding an old protocol version in code
Detailed fix by platform
curl
- bash
curl -v --tlsv1.2 https://api.example.com/ openssl s_client -connect api.example.com:443 -tls1_2
Java
- java
// Java 8u261+ supports TLS 1.3; at minimum allow 1.2 System.setProperty("https.protocols", "TLSv1.2,TLSv1.3");
.NET
ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12 | SecurityProtocolType.Tls13; // legacy .NET Framework only
How to diagnose
- Server — Which TLS versions/ciphers does it accept (SSL Labs, openssl s_client)?
- Client — Runtime and OpenSSL version
- Proxy — Is anything intercepting TLS?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026