TLS Version and Cipher Mismatch: Negotiation Failures
· CSR.plus Team

- •Handshake failure with "no shared cipher" or a protocol version error means the two sides share no compatible TLS option.
- •Check the server’s enabled versions and suites against what your client supports.
- •Enable a broad, modern set: TLS 1.2 + 1.3 with the standard ECDHE AES-GCM suites.
What "no shared cipher" means
During negotiation the client sends its supported cipher suites; the server picks one it also supports. If the intersection is empty, OpenSSL reports "no protocols available" or "no shared cipher". The same root cause shows up in browsers as ERR_SSL_VERSION_OR_CIPHER_MISMATCH. Old clients combined with a server that only enables TLS 1.3 + modern suites are the classic trigger.
Reading openssl output
openssl s_client -connect host:443 -servername host prints "Protocol : TLSv1.3" and "Cipher : TLS_AES_256_GCM_SHA384" on success. On failure you get "no protocols available" (version gap) or "no shared cipher". Use openssl ciphers -v to list what the server build offers, and s_client -tls1_2 / -tls1_3 to test each version separately.
The right server configuration
Enable TLS 1.2 and TLS 1.3 and disable everything below. Keep the standard modern suites: TLS_AES_256_GCM_SHA384 and TLS_AES_128_GCM_SHA256 for 1.3; ECDHE-ECDSA/ECDHE-RSA with AES-256-GCM and AES-128-GCM for 1.2. Only add legacy suites if you genuinely support old clients, and document the trade-off.
FAQ
Do I need TLS 1.0/1.1 for old devices?
All major browsers and OSes have disabled TLS 1.0/1.1. Supporting them for old embedded devices is a compatibility decision — isolate those clients on a separate vhost if needed.
Can HTTP/3 help with old clients?
No — HTTP/3 runs over QUIC/TLS 1.3 and old clients do not speak it. HTTP/2 and HTTP/3 coexist; the negotiation problem is at the TLS layer.
UptimeRobot
Monitor your SSL & uptime for free
UptimeRobot watches your certificates and endpoints 24/7 — 50 monitors on the free plan.
Affiliate link — we may earn a commission at no extra cost to you.
Free SSL/TLS tools
Verify and inspect your certificates in seconds.