< HTTP/1.1 526 Invalid SSL Certificate526 Invalid SSL Certificate (Cloudflare)
Cloudflare 526 means the origin certificate failed Full (strict) validation. Check expiry, hostname and chain with openssl, then fix it.
- Cacheable
- No
- Retry?
- No: fix the origin certificate
- Usually sent by
- Cloudflare edge
On this page
TL;DR: In Full (strict) mode Cloudflare verifies the origin certificate. 526 means that check failed: it is expired, does not cover the hostname Cloudflare asked for, is not issued by a trusted CA, or the server is not sending the intermediate certificates. Check it with
openssl s_client, then fix or install a Cloudflare Origin CA certificate.
What it means
The handshake succeeded (otherwise you would see 525), so the origin speaks TLS. Cloudflare then validated the leaf certificate against the SNI hostname it used and found a problem. The error page reads Error 526: Invalid SSL certificate, with Server: cloudflare and a CF-RAY header like every Cloudflare-generated error.
Full vs Full (strict):
| Check | Full | Full (strict) |
|---|---|---|
| Origin must speak TLS | Yes | Yes |
| Expiry checked | No | Yes |
| Hostname must match SAN | No | Yes |
| Must chain to a public CA or Cloudflare Origin CA | No | Yes |
Check the certificate the way Cloudflare sees it
Use the origin IP directly with SNI set to the hostname:
echo | openssl s_client -connect 203.0.113.10:443 -servername www.example.com -showcerts 2>/dev/null \
| openssl x509 -noout -subject -issuer -dates -ext subjectAltName
subject=CN = www.example.com
issuer=C = US, O = Let's Encrypt, CN = R11
notBefore=Aug 1 00:00:00 2026 GMT
notAfter=Oct 30 23:59:59 2026 GMT
X509v3 Subject Alternative Name:
DNS:example.com, DNS:www.example.com
Verify the whole thing, including chain and hostname:
openssl s_client -connect 203.0.113.10:443 -servername www.example.com -verify_hostname www.example.com -verify_return_error </dev/null
Look at the last lines: Verify return code: 0 (ok) is what you want. Common failures:
Verify return code: 10 (certificate has expired)
Verify return code: 18 (self-signed certificate)
Verify return code: 20 (unable to get local issuer certificate) # missing intermediates
Verify return code: 62 (hostname mismatch)
Count the certificates in the chain: openssl s_client ... -showcerts should print the leaf plus intermediates, as Certificate chain entries 0 s: and 1 s:. If only entry 0 appears with a public CA issuer, the server is not sending intermediates.
Causes, ordered by likelihood
- Expired certificate. An ACME renewal job silently failing, or a Cloudflare Origin CA certificate (valid up to 15 years but chosen at issue time) that was issued with a short validity.
- Hostname not in SAN. The certificate covers
example.combut the request is forwww.example.com, or a wildcard*.example.comthat does not covera.b.example.com. Wildcards match one label. - Missing intermediate certificate. The server sends only the leaf. Many browsers fetch missing intermediates; Cloudflare’s origin validation will not. Install
fullchain.peminstead ofcert.pem. - Self-signed or private CA certificate while in strict mode.
- A different certificate served for the SNI name than you think: the default vhost’s certificate answering because the SNI-specific
serverblock is not matched. - Hostname mismatch from rewriting: an Origin Rule changes the Host or SNI to a name your certificate does not cover.
Fix it
Use the certificate chain file with nginx:
ssl_certificate /etc/letsencrypt/live/www.example.com/fullchain.pem; # leaf + intermediates
ssl_certificate_key /etc/letsencrypt/live/www.example.com/privkey.pem;
Apache: SSLCertificateFile should point to the leaf and SSLCertificateChainFile (or the combined file in 2.4.8+) to the intermediates.
If you do not want to manage public certificates at the origin, issue a Cloudflare Origin CA certificate under SSL/TLS > Origin Server, install it on the origin and keep Full (strict). It is trusted by Cloudflare only: direct browser access to the origin IP will show a warning, which is fine, and arguably desirable.
Temporarily switching to Full gets traffic flowing, but it silently removes validation, so a later expired or impersonated origin goes unnoticed. Treat it as a short diagnostic step, not the fix. Combine strict mode with Authenticated Origin Pulls or Cloudflare Tunnel if you also need the origin to reject non-Cloudflare traffic.
Related
- 525 SSL Handshake Failed: the handshake itself failed.
- 530 Origin DNS Error
- 521 Web Server Is Down
- 520 Web Server Returned an Unknown Error
- HTTPS and TLS: certificates and chains.
Frequently asked questions
What does Cloudflare error 526 mean?
Cloudflare completed a TLS handshake with your origin, but the certificate it presented failed validation required by Full (strict) mode. It is expired, issued for a different hostname, not chained to a trusted authority, or missing intermediates.
Why do I get 526 only in Full (strict) mode?
Full mode accepts any certificate on the origin, including self-signed and expired ones, because it encrypts without verifying. Full (strict) requires a certificate that is valid, unexpired, matches the hostname, and is signed by a public CA or a Cloudflare Origin CA certificate.
Does Cloudflare accept a self-signed origin certificate?
In Full mode yes, in Full (strict) no. For a certificate you generate yourself that Cloudflare will trust in strict mode, use a Cloudflare Origin CA certificate, which is trusted only by Cloudflare edge servers and free to issue.
My certificate is valid in the browser but Cloudflare returns 526. Why?
The browser is validating the Cloudflare edge certificate, not your origin one. Test the origin directly with openssl s_client against its IP, and check that the server sends the full chain, not only the leaf certificate, since browsers can fetch missing intermediates but Cloudflare will not.
Which names does Cloudflare check on the origin certificate?
It checks the hostname against the Subject Alternative Name list, not the Common Name. A certificate for the apex domain only, or a wildcard that covers one label fewer than the hostname, is a typical mismatch. Fix the SAN list rather than relying on the CN.
Sources
Related
525 SSL Handshake Failed (Cloudflare)
Cloudflare 525 means the TLS handshake with your origin server failed. Diagnose with openssl s_client, check SSL modes, ciphers, SNI and port 443, and fix it.
520 Web Server Returned an Unknown Error
Cloudflare-specific error when the origin server returns an unexpected response. Learn about 520 errors and how to troubleshoot them.
521 Web Server Is Down
Cloudflare-specific status code indicating the origin server refused the connection. Learn about this proxy error and how to troubleshoot it.
522 Connection Timed Out
Cloudflare-specific error when unable to establish a TCP connection to the origin server. Learn how to diagnose and fix 522 timeout errors.