Nginx 400: The SSL certificate error (495 / 496 client certificate)
Nginx rejected the request because the client certificate was invalid (495) or missing (496) on a site that requires mutual TLS.
Seen on:
REST API
Meaning
When ssl_verify_client is on, Nginx expects the client to present a certificate signed by the configured CA. Nginx logs 495 (certificate error) or 496 (no certificate) internally but shows the user “400 Bad Request — The SSL certificate error” or “No required SSL certificate was sent”.
Common causes
- Client didn’t send a certificate (496)
- Certificate expired, not yet valid, or signed by another CA (495)
- ssl_client_certificate missing the intermediate CA
- ssl_verify_depth too low for the chain
⚡ Quick fix
- Send the client certificate and key with the request
- Check the client cert chain against ssl_client_certificate
- Use ssl_verify_client optional for paths that don’t need mTLS
Detailed fix by platform
curl
curl --cert client.crt --key client.key https://api.example.com/
Nginx
- nginx
ssl_client_certificate /etc/nginx/ca-chain.pem; ssl_verify_client on; ssl_verify_depth 2;
How to diagnose
- Certificate — openssl x509 -in client.crt -noout -dates -issuer
- Chain — Is the issuing CA in ssl_client_certificate?
- Log — 495 or 496 in access log?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in HTTP
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026