SSL Handshake Failed
Client and server could not agree on a TLS version or cipher, or the server has no certificate for the name requested (SNI). Check the site below to confirm what is wrong.
- Free
- No Sign-Up
- Live Lookup
Examples:
SSL Certificate Checker
The error, and the fix
Error CodesSSL_ERROR_HANDSHAKE_FAILURE · ERR_SSL_VERSION_OR_CIPHER_MISMATCH
Usual CauseClient and server could not agree on a TLS version or cipher, or the server has no certificate for the name requested (SNI)
Check From a Terminalopenssl s_client -connect example.com:443 -servername example.com
Client and server could not agree on a TLS version or cipher, or the server has no certificate for the name requested (SNI).
How to fix it: Enable TLS 1.2 and 1.3 with modern ciphers, and make sure a server block exists for the exact host name.
Questions
What does "ssl handshake failed" mean?
Client and server could not agree on a TLS version or cipher, or the server has no certificate for the name requested (SNI).
How do I fix it?
Enable TLS 1.2 and 1.3 with modern ciphers, and make sure a server block exists for the exact host name.
Is it safe to click through the warning?
Not on a site where you enter passwords or payment details: the connection may not be private. Fix the certificate instead.
Free Tools
More tools
SSL Certificate CheckerExpiry, issuer, chain, names and TLS version for any HTTPS site.DNS LookupA, AAAA, MX, NS, TXT, CNAME, SOA and CAA records for any domain.SPF CheckerValidate an SPF record and count its DNS lookups against the limit of 10.Firewall Rule GeneratorGenerate iptables, nftables and UFW rules for common server set-ups.
Stop abuse leaving your servers
Frabs watches every VM's outbound traffic and stops spam, scans and floods before the abuse report arrives.