Cloudflare Error 526: Invalid SSL Certificate

With SSL mode Full (strict), the origin’s certificate is expired, self-signed, or doesn’t match the hostname.

Seen on: Cloudflare Linux

Meaning

Full (strict) validates the origin certificate like a browser would (except it also trusts Cloudflare Origin CA certificates). The handshake works, but the certificate fails validation.

Common causes

  • Origin certificate expired (Let’s Encrypt renewal failed)
  • Self-signed certificate
  • Hostname not covered by the certificate
  • Missing intermediate chain

⚡ Quick fix

  1. Renew the origin certificate (certbot renew) and reload the web server
  2. Use a Cloudflare Origin CA certificate (valid up to 15 years)
  3. Ensure the cert covers the exact hostname
  4. Serve the full chain

Detailed fix by platform

Linux

  1. Check expiry and names on the origin:
    bash
    echo | openssl s_client -connect ORIGIN_IP:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates -ext subjectAltName
    sudo certbot renew --dry-run

How to diagnose

  1. Expiry — notAfter date?
  2. Names — SAN includes the hostname?
  3. Issuer — Public CA or Cloudflare Origin CA?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.