Cloudflare Error 525: SSL Handshake Failed

Cloudflare couldn’t complete a TLS handshake with your origin (SSL mode Full / Full strict).

Seen on: Cloudflare Nginx

Meaning

The origin accepted TCP on 443 but TLS failed: no certificate configured, no SNI support, incompatible ciphers/protocols, or port 443 serving plain HTTP.

Common causes

  • No SSL certificate installed on the origin
  • Origin listens on 443 without TLS
  • Origin doesn’t support SNI or TLS 1.2+
  • Cipher mismatch
  • Firewall dropping TLS from Cloudflare IPs

⚡ Quick fix

  1. Install a certificate on the origin (Cloudflare Origin CA or Let’s Encrypt)
  2. Test: openssl s_client -connect ORIGIN_IP:443 -servername example.com
  3. Enable TLS 1.2/1.3 on the origin
  4. Temporarily switch SSL mode to Flexible only to confirm (not a fix)

Detailed fix by platform

Nginx

  1. Origin TLS with a Cloudflare Origin CA cert:
    nginx
    server {
        listen 443 ssl http2;
        server_name example.com;
        ssl_certificate     /etc/ssl/cloudflare/origin.pem;
        ssl_certificate_key /etc/ssl/cloudflare/origin.key;
        ssl_protocols TLSv1.2 TLSv1.3;
    }

How to diagnose

  1. Origin TLS — openssl s_client against the origin IP
  2. SSL mode — Full / Full (strict)?
  3. Protocols — TLS 1.2+ enabled?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.