ERR_SSL_VERSION_OR_CIPHER_MISMATCH on a Cloudflare site (certificate not issued / multi-level subdomain)
Cloudflare has no edge certificate for the hostname — the Universal SSL cert is still pending, or the hostname is a second-level subdomain (a.b.example.com) not covered.
Seen on:
Cloudflare
Meaning
Universal SSL covers example.com and *.example.com only. dev.api.example.com needs Advanced Certificate Manager or a total TLS setup. Newly added zones need minutes to hours for issuance; CAA records can block it.
Common causes
- Multi-level subdomain (a.b.example.com) not covered by Universal SSL
- Certificate still being issued after adding the zone
- CAA records not allowing Cloudflare’s CAs
- Universal SSL disabled
⚡ Quick fix
- Use a first-level subdomain or order an Advanced certificate
- Wait for issuance; check SSL/TLS → Edge Certificates
- Fix CAA records to allow Cloudflare’s CAs
Detailed fix by platform
Shell
- bash
dig +short CAA example.com openssl s_client -connect dev.api.example.com:443 -servername dev.api.example.com </dev/null 2>&1 | head -5
How to diagnose
- Hostname — Levels deep?
- Certificates — Edge Certificates status
- CAA — Records present?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Cloudflare
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026