Error Reference › SSL / DNS
SSL / DNS

SSL handshake / protocol error

The client and server couldn't agree on a secure connection.

What it looks like

ERR_SSL_VERSION_OR_CIPHER_MISMATCH
curl: (35) OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to example.com:443

What does "SSL handshake / protocol error" mean?

Raised when the client and server fail to set up an encrypted connection before any HTTP happens. The usual causes are an old client meeting a server that only allows modern TLS, a misconfigured server, or a proxy or antivirus intercepting the connection.

What causes "SSL handshake / protocol error"?

  • TLS version/cipher mismatch (old client vs modern server).
  • Misconfigured TLS on the server.
  • Something intercepting TLS (proxy/AV).

How do I confirm the cause?

  1. Test the server with openssl s_client -connect host:443 -servername host, or an online checker such as SSL Labs, to see which TLS versions it accepts.
  2. Check whether it fails from every client or only some — only old clients points to TLS versions; only one network points to a proxy.
  3. Temporarily disable HTTPS scanning in antivirus or a corporate proxy to see whether the handshake then succeeds.

How do I fix "SSL handshake / protocol error"?

  • Check supported TLS versions/ciphers on both ends.
  • Test with SSL Labs / openssl s_client.
  • Disable TLS-intercepting proxies/AV to isolate.

How do I stop it happening again?

  • Serve TLS 1.2 and 1.3 with a current recommended configuration, and retest after server upgrades.
  • Keep clients and their TLS libraries updated.
Got a different error? Paste it into the Explain This Error tool → Identifies the family and the fix — runs locally, nothing uploaded.

Related errors