Cloudflare Error 526: Invalid SSL Certificate
With SSL mode Full (strict), the origin’s certificate is expired, self-signed, or doesn’t match the hostname.
Meaning
Full (strict) validates the origin certificate like a browser would (except it also trusts Cloudflare Origin CA certificates). The handshake works, but the certificate fails validation.
Common causes
- Origin certificate expired (Let’s Encrypt renewal failed)
- Self-signed certificate
- Hostname not covered by the certificate
- Missing intermediate chain
⚡ Quick fix
- Renew the origin certificate (
certbot renew) and reload the web server - Use a Cloudflare Origin CA certificate (valid up to 15 years)
- Ensure the cert covers the exact hostname
- Serve the full chain
Detailed fix by platform
Linux
- Check expiry and names on the origin:bash
echo | openssl s_client -connect ORIGIN_IP:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates -ext subjectAltName sudo certbot renew --dry-run
How to diagnose
- Expiry — notAfter date?
- Names — SAN includes the hostname?
- Issuer — Public CA or Cloudflare Origin CA?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026