How HTTP Works
5xx · Server errorNon-standard · Cloudflare
< HTTP/1.1 526 Invalid SSL Certificate

526 Invalid SSL Certificate (Cloudflare)

Cloudflare 526 means the origin certificate failed Full (strict) validation. Check expiry, hostname and chain with openssl, then fix it.

Reviewed 3 min readintermediate4 sourcesTry itMarkdown
Cacheable
No
Retry?
No: fix the origin certificate
Usually sent by
Cloudflare edge
Spec
Cloudflare error 526
On this page

TL;DR: In Full (strict) mode Cloudflare verifies the origin certificate. 526 means that check failed: it is expired, does not cover the hostname Cloudflare asked for, is not issued by a trusted CA, or the server is not sending the intermediate certificates. Check it with openssl s_client, then fix or install a Cloudflare Origin CA certificate.

What it means

The handshake succeeded (otherwise you would see 525), so the origin speaks TLS. Cloudflare then validated the leaf certificate against the SNI hostname it used and found a problem. The error page reads Error 526: Invalid SSL certificate, with Server: cloudflare and a CF-RAY header like every Cloudflare-generated error.

Full vs Full (strict):

CheckFullFull (strict)
Origin must speak TLSYesYes
Expiry checkedNoYes
Hostname must match SANNoYes
Must chain to a public CA or Cloudflare Origin CANoYes

Check the certificate the way Cloudflare sees it

Use the origin IP directly with SNI set to the hostname:

echo | openssl s_client -connect 203.0.113.10:443 -servername www.example.com -showcerts 2>/dev/null \
  | openssl x509 -noout -subject -issuer -dates -ext subjectAltName
subject=CN = www.example.com
issuer=C = US, O = Let's Encrypt, CN = R11
notBefore=Aug  1 00:00:00 2026 GMT
notAfter=Oct 30 23:59:59 2026 GMT
X509v3 Subject Alternative Name:
    DNS:example.com, DNS:www.example.com

Verify the whole thing, including chain and hostname:

openssl s_client -connect 203.0.113.10:443 -servername www.example.com -verify_hostname www.example.com -verify_return_error </dev/null

Look at the last lines: Verify return code: 0 (ok) is what you want. Common failures:

Verify return code: 10 (certificate has expired)
Verify return code: 18 (self-signed certificate)
Verify return code: 20 (unable to get local issuer certificate)   # missing intermediates
Verify return code: 62 (hostname mismatch)

Count the certificates in the chain: openssl s_client ... -showcerts should print the leaf plus intermediates, as Certificate chain entries 0 s: and 1 s:. If only entry 0 appears with a public CA issuer, the server is not sending intermediates.

Causes, ordered by likelihood

  1. Expired certificate. An ACME renewal job silently failing, or a Cloudflare Origin CA certificate (valid up to 15 years but chosen at issue time) that was issued with a short validity.
  2. Hostname not in SAN. The certificate covers example.com but the request is for www.example.com, or a wildcard *.example.com that does not cover a.b.example.com. Wildcards match one label.
  3. Missing intermediate certificate. The server sends only the leaf. Many browsers fetch missing intermediates; Cloudflare’s origin validation will not. Install fullchain.pem instead of cert.pem.
  4. Self-signed or private CA certificate while in strict mode.
  5. A different certificate served for the SNI name than you think: the default vhost’s certificate answering because the SNI-specific server block is not matched.
  6. Hostname mismatch from rewriting: an Origin Rule changes the Host or SNI to a name your certificate does not cover.

Fix it

Use the certificate chain file with nginx:

ssl_certificate     /etc/letsencrypt/live/www.example.com/fullchain.pem;  # leaf + intermediates
ssl_certificate_key /etc/letsencrypt/live/www.example.com/privkey.pem;

Apache: SSLCertificateFile should point to the leaf and SSLCertificateChainFile (or the combined file in 2.4.8+) to the intermediates.

If you do not want to manage public certificates at the origin, issue a Cloudflare Origin CA certificate under SSL/TLS > Origin Server, install it on the origin and keep Full (strict). It is trusted by Cloudflare only: direct browser access to the origin IP will show a warning, which is fine, and arguably desirable.

Temporarily switching to Full gets traffic flowing, but it silently removes validation, so a later expired or impersonated origin goes unnoticed. Treat it as a short diagnostic step, not the fix. Combine strict mode with Authenticated Origin Pulls or Cloudflare Tunnel if you also need the origin to reject non-Cloudflare traffic.

Frequently asked questions

What does Cloudflare error 526 mean?

Cloudflare completed a TLS handshake with your origin, but the certificate it presented failed validation required by Full (strict) mode. It is expired, issued for a different hostname, not chained to a trusted authority, or missing intermediates.

Why do I get 526 only in Full (strict) mode?

Full mode accepts any certificate on the origin, including self-signed and expired ones, because it encrypts without verifying. Full (strict) requires a certificate that is valid, unexpired, matches the hostname, and is signed by a public CA or a Cloudflare Origin CA certificate.

Does Cloudflare accept a self-signed origin certificate?

In Full mode yes, in Full (strict) no. For a certificate you generate yourself that Cloudflare will trust in strict mode, use a Cloudflare Origin CA certificate, which is trusted only by Cloudflare edge servers and free to issue.

My certificate is valid in the browser but Cloudflare returns 526. Why?

The browser is validating the Cloudflare edge certificate, not your origin one. Test the origin directly with openssl s_client against its IP, and check that the server sends the full chain, not only the leaf certificate, since browsers can fetch missing intermediates but Cloudflare will not.

Which names does Cloudflare check on the origin certificate?

It checks the hostname against the Subject Alternative Name list, not the Common Name. A certificate for the apex domain only, or a wildcard that covers one label fewer than the hostname, is a typical mismatch. Fix the SAN list rather than relying on the CN.

Sources

  1. Cloudflare: Error 526 Invalid SSL certificatedevelopers.cloudflare.com
  2. Cloudflare: SSL/TLS encryption modesdevelopers.cloudflare.com
  3. Cloudflare: Origin CA certificatesdevelopers.cloudflare.com
  4. RFC 5280: X.509 Certificate and CRL Profilerfc-editor.org

Keep going

Browse /search