← Back to Articles
Troubleshooting2026-08-15•5 min read

SSL Handshake Failed: 11 Causes and How to Fix Them

· CSR.plus Team

SSL Handshake Failed: 11 Causes and How to Fix Them
  • •A failed handshake almost always traces to one of 11 causes: certificate, cipher, SNI, protocol, or network layer.
  • •Diagnose in order: expiry, hostname match, chain completeness, then TLS versions and ciphers.
  • •Most handshake failures are fixed with a correct intermediate chain or a supported cipher suite.
Chain
Most common cause
missing intermediate certificate
Cipher
2nd most common
server/client suite mismatch
<10 min
Typical fix time
once correctly diagnosed
All
Browsers affected
same root causes everywhere

What actually happens when a handshake fails

During the TLS handshake the client and server must agree on a protocol version, a cipher suite and a valid certificate chain. Failure at any step aborts the connection. Common failure points are certificate expiry, a hostname not covered by the certificate, an incomplete chain (the server sends the leaf but not the intermediate), an unsupported TLS version, a cipher mismatch, missing SNI, or a firewall/NAT dropping the ClientHello.

How to diagnose in under a minute

Run openssl s_client -connect yourdomain.com:443 -servername yourdomain.com and read the output. "Verify return code: 0" means the chain is fine. "unable to get local issuer certificate" points to a missing intermediate. "no peer certificate available" or an empty line after CONNECTED means the server never completed the handshake — a protocol or cipher problem. Browser console errors add the client-side view.

Fixes for the 5 most frequent causes

1) Missing intermediate: download the CA bundle and concatenate leaf + intermediate in the right order. 2) Cipher mismatch: enable a common suite like TLS_AES_256_GCM_SHA384 (TLS 1.3) or ECDHE-RSA-AES256-GCM (TLS 1.2). 3) TLS version: enable TLS 1.2 and 1.3 and disable below 1.2 on the server. 4) Hostname/SNI: make sure the certificate includes the exact hostname and that SNI is enabled. 5) Network: check that port 443 is open, and that a load balancer or CDN is not terminating TLS with its own settings.

FAQ

Why does the handshake fail in the browser but work in curl?

Different clients accept different TLS versions and cipher suites. If it works in curl but not in an old browser, the client does not support the negotiated TLS version — enable TLS 1.2 as the minimum.

Can a firewall cause handshake failures?

Yes. Some firewalls and NAT devices drop large ClientHello packets or block TCP ports silently. Test with a non-standard port or packet capture to confirm.

UptimeRobot

Monitor your SSL & uptime for free

UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.

Try UptimeRobot FREE

Affiliate link — we may earn a commission at no extra cost to you.

Free SSL/TLS tools

Verify and inspect your certificates in seconds.

Related articles