495 🌐 HTTP

Nginx 400: The SSL certificate error (495 / 496 client certificate)

Nginx rejected the request because the client certificate was invalid (495) or missing (496) on a site that requires mutual TLS.

Seen on: REST API

Meaning

When ssl_verify_client is on, Nginx expects the client to present a certificate signed by the configured CA. Nginx logs 495 (certificate error) or 496 (no certificate) internally but shows the user “400 Bad Request — The SSL certificate error” or “No required SSL certificate was sent”.

Common causes

  • Client didn’t send a certificate (496)
  • Certificate expired, not yet valid, or signed by another CA (495)
  • ssl_client_certificate missing the intermediate CA
  • ssl_verify_depth too low for the chain

⚡ Quick fix

  1. Send the client certificate and key with the request
  2. Check the client cert chain against ssl_client_certificate
  3. Use ssl_verify_client optional for paths that don’t need mTLS

Detailed fix by platform

curl

  1. curl --cert client.crt --key client.key https://api.example.com/

Nginx

  1. nginx
    ssl_client_certificate /etc/nginx/ca-chain.pem;
    ssl_verify_client on;
    ssl_verify_depth 2;

How to diagnose

  1. Certificate — openssl x509 -in client.crt -noout -dates -issuer
  2. Chain — Is the issuing CA in ssl_client_certificate?
  3. Log — 495 or 496 in access log?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.