ERR_SSL_VERSION_OR_CIPHER_MISMATCH (Cloudflare) 🟧 Cloudflare

ERR_SSL_VERSION_OR_CIPHER_MISMATCH on a Cloudflare site (certificate not issued / multi-level subdomain)

Cloudflare has no edge certificate for the hostname — the Universal SSL cert is still pending, or the hostname is a second-level subdomain (a.b.example.com) not covered.

Seen on: Cloudflare

Meaning

Universal SSL covers example.com and *.example.com only. dev.api.example.com needs Advanced Certificate Manager or a total TLS setup. Newly added zones need minutes to hours for issuance; CAA records can block it.

Common causes

  • Multi-level subdomain (a.b.example.com) not covered by Universal SSL
  • Certificate still being issued after adding the zone
  • CAA records not allowing Cloudflare’s CAs
  • Universal SSL disabled

⚡ Quick fix

  1. Use a first-level subdomain or order an Advanced certificate
  2. Wait for issuance; check SSL/TLS → Edge Certificates
  3. Fix CAA records to allow Cloudflare’s CAs

Detailed fix by platform

Shell

  1. bash
    dig +short CAA example.com
    openssl s_client -connect dev.api.example.com:443 -servername dev.api.example.com </dev/null 2>&1 | head -5

How to diagnose

  1. Hostname — Levels deep?
  2. Certificates — Edge Certificates status
  3. CAA — Records present?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.