Error guide

526 Invalid SSL Certificate

Cloudflare reached your origin over HTTPS and rejected the certificate it presented.

526 means Cloudflare connected to your origin over HTTPS, got far enough into the handshake to read the certificate, and rejected it. It only happens under the Full (strict) SSL mode, which validates the origin's certificate. Under Full, Cloudflare would have accepted the same certificate without checking it.

The reasons are the ones a browser would reject a certificate for: it has expired, it has been revoked, it is self-signed or issued by an authority Cloudflare does not trust, or the hostname being requested is not in its common name or subject alternative names. It is the certificate on your origin that failed, not the one visitors see at the edge.

The fix is a certificate Cloudflare will accept. Any publicly trusted certificate works, and Cloudflare also issues free, long-lived Origin CA certificates that only Cloudflare trusts, which suit an origin nothing else connects to directly. Custom Origin Trust Store lets Cloudflare trust your own private authority. Switching to Full makes the error go away by no longer checking at all.

Common causes

  • An origin certificate that expired after an automated renewal failed without anyone noticing.
  • A self-signed certificate on the origin.
  • A certificate whose names do not include the hostname Cloudflare requests.
  • An incomplete certificate chain, which strict mode rejects and browsers often paper over.
  • A certificate from a private or untrusted authority, or one that has been revoked.

How to diagnose it

  1. Run openssl s_client -connect <origin-ip>:443 -servername <hostname> -showcerts and read the certificate the origin actually serves.
  2. Check the expiry date first: it is the most common cause and the quickest to confirm.
  3. Compare the certificate's subject and alternative names with the hostname Cloudflare requests.
  4. Confirm the chain includes the intermediate certificates, not only the leaf.
  5. If the certificate renews automatically, read the renewal job's logs for its last run.

Whose fault is it? The server's side

Origin-side. Strict mode is doing exactly what it is for, and the certificate on your origin fails the check. The fix is a valid certificate there, not a weaker SSL mode.

What monitoring sees

The visitor-facing check fails on the 526 without seeing why. An SSL Certificate monitor pointed at the origin reads the certificate itself, and an Expires In Days criterion on it warns before an expiry turns into a 526. Its Is Valid Certificate criterion validates against the name the monitor connects to, so it answers Cloudflare's question only when that is the hostname Cloudflare requests, and it reports a Cloudflare Origin CA certificate as not valid, because only Cloudflare trusts one.

Questions

What is the difference between 525 and 526?

525 means the TLS handshake with your origin failed outright: no certificate, nothing on port 443, or no protocol in common. 526 means the handshake got far enough for Cloudflare to read the certificate, and under Full (strict) it rejected what it read.

Will a Cloudflare Origin CA certificate fix 526?

Yes, if Cloudflare is the only thing that connects to your origin. Cloudflare trusts its own Origin CA certificates under Full (strict), but browsers and other clients do not, so anything reaching the origin directly will see an untrusted certificate.

One of the Uptimely HTTP and network error guides, written for the person who operates the server rather than the one refreshing the page. Something here read wrong to you? Email support@getuptimely.com.