Skip to main content
DigiCert, Sectigo and GeoTrust SSL certificates
+90 850 259 76 06 WhatsApp Support Become a Reseller
SSL Certificates
Brands
Code Signing LEI Code
Tools
Support Contact WhatsApp Cart
Language
Currency
Get an SSL Certificate
SSL Security

Cloudflare SSL Errors: 525, 526 and Configuration Issues Solution

Cloudflare SSL errors: Solution guide to Error 525 SSL Handshake Failed, Error 526 Invalid SSL Certificate, mixed content and redirect loop problems.

11 min read

Cloudflare SSL Architecture

Cloudflare works as a reverse proxy between your website and your visitors. SSL connections occur in two stages:

  1. Visitor ↔ Cloudflare: Cloudflare's Universal SSL certificate is used
  2. Cloudflare ↔ Origin Server:The SSL certificate from your origin server is used (in Full/Strict mode)

Due to this two-layer structure, Cloudflare-specific SSL errors may occur.

Cloudflare SSL Modes

ModeVisitor ↔ CFCF ↔ OriginOrigin SSL Required?
OffHTTPHTTPNo
FlexibleHTTPSHTTPNo
FullHTTPSHTTPSSelf-signed sufficient
Full (Strict)HTTPSHTTPSValid certificate

Error 525: SSL Handshake Failed

This error occurs when the SSL handshake between Cloudflare and the origin server fails.

Causes

  • There is no SSL certificate on the origin server (in Full/Strict mode)
  • Origin certificate is self-signed and mode is "Full (Strict)"
  • Older TLS version (TLS 1.0/1.1) on origin server
  • Certificate and key mismatch
  • Origin server not listening on port 443

Solution

  1. Install SSL certificate on origin server (Cloudflare Origin Certificate is free)
  2. Set SSL mode to "Full" or "Full (Strict)"
  3. Enable TLS 1.2+
  4. Make sure port 443 is open and configured correctly
# Creating a Cloudflare Origin Certificate:
# Dashboard → SSL/TLS → Origin Server → Create Certificate
# Validity: Up to 15 years (only works behind Cloudflare proxy)

Error 526: Invalid SSL Certificate

In "Full (Strict)" mode, this error occurs if the SSL certificate on the origin server is invalid or unreliable.

Causes

  • Origin certificate has expired
  • Self-signed certificate (rejected in Strict mode)
  • The certificate does not match the domain
  • Intermediate certificate chain is missing

Solution

  • Use valid certificate from trusted CA or create Cloudflare Origin Certificate
  • Change SSL mode to "Full" (workaround — accepts self-signed)
  • Verify that your origin certificate matches the domain and the intermediate chain is complete

Error 521/522: Origin Access Problems

Although it is not a direct SSL error, it may be related to the SSL configuration:

  • 521 (Web Server is Down): Origin server is down. Start the web server.
  • 522 (Connection Timed Out): Cloudflare cannot reach origin. Whitelist Cloudflare IPs in Firewall.
# Whitelist Cloudflare IP ranges
# https://www.cloudflare.com/ips/
# With Nginx:
allow 173.245.48.0/20;
allow 103.21.244.0/22;
allow 103.22.200.0/22;
allow 103.31.4.0/22;
allow 141.101.64.0/18;
allow 108.162.192.0/18;
allow 190.93.240.0/20;
allow 188.114.96.0/20;
allow 197.234.240.0/22;
allow 198.41.128.0/17;
deny all;

Redirect Loop

In "Flexible" SSL mode, if there is HTTP→HTTPS redirection on the origin server, an infinite loop occurs.

Solution

  • Best: Set SSL mode to "Full (Strict)" and use real SSL certificate on origin
  • Alternative: Remove HTTP→HTTPS redirect on origin server (in Flexible mode)
  • Enable the "Always Use HTTPS" feature in Cloudflare Dashboard

Mixed Content Problems

When Cloudflare is in "Flexible" mode, http:// URLs are generated in the code because the origin works as HTTP. Mixed Content occurs because the visitor connects via HTTPS.

Solution

  • Cloudflare Dashboard → SSL/TLS → Edge Certificates → Enable "Automatic HTTPS Rewrites"
  • Install SSL at Origin and switch to "Full (Strict)" mode (root solution)

Cloudflare SSL Configuration Checklist

ControlRecommended Setting
SSL ModeFull (Strict)
Always Use HTTPSOn
Automatic HTTPS RewritesOn
Minimum TLS VersionTLS 1.2
TLS 1.3On
HSTSActive (max-age: 1 year)
Origin CertificateInstalled

Conclusion

Cloudflare SSL errors are usually caused by choosing the wrong SSL mode. The combination of "Full (Strict)" mode + valid SSL certificate on the origin server prevents most 525, 526 and redirect loop errors. Cloudflare Origin Certificate offers a solution that is free and valid for up to 15 years.

Share this post
Ali Yiğit
Yazar

Ali Yiğit

Recommended SSL Certificates

All Products
EV Certum

Certum Premium EV Multi-Domain SSL

Protect multiple domains at EV level with Certum Premium EV Multi-Domain SSL. Company name visible i

€372.38 /yr
Details
EV Certum

Certum Premium EV SSL

Get the most comprehensive identity validation with Certum Premium EV SSL. Extended validation, comp

€581.75 /yr
Details
OV Certum

Certum Trusted Multi-Domain SSL

Protect multiple domains at OV level with Certum Trusted Multi-Domain SSL. Company name visible, 4,

€44.44 /yr
Details