Error Reference › SSL / DNS
SSL / DNS
SSL handshake / protocol error
The client and server couldn't agree on a secure connection.
What it looks like
ERR_SSL_VERSION_OR_CIPHER_MISMATCH
curl: (35) OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to example.com:443
What does "SSL handshake / protocol error" mean?
Raised when the client and server fail to set up an encrypted connection before any HTTP happens. The usual causes are an old client meeting a server that only allows modern TLS, a misconfigured server, or a proxy or antivirus intercepting the connection.
What causes "SSL handshake / protocol error"?
- TLS version/cipher mismatch (old client vs modern server).
- Misconfigured TLS on the server.
- Something intercepting TLS (proxy/AV).
How do I confirm the cause?
- Test the server with openssl s_client -connect host:443 -servername host, or an online checker such as SSL Labs, to see which TLS versions it accepts.
- Check whether it fails from every client or only some — only old clients points to TLS versions; only one network points to a proxy.
- Temporarily disable HTTPS scanning in antivirus or a corporate proxy to see whether the handshake then succeeds.
How do I fix "SSL handshake / protocol error"?
- Check supported TLS versions/ciphers on both ends.
- Test with SSL Labs / openssl s_client.
- Disable TLS-intercepting proxies/AV to isolate.
How do I stop it happening again?
- Serve TLS 1.2 and 1.3 with a current recommended configuration, and retest after server upgrades.
- Keep clients and their TLS libraries updated.