What is SSL/TLS Handshake?
SSL/TLS Handshake (handshake) is a series of steps that occur before a secure connection is established between the browser and the server. In this process, authentication, protocol and encryption method are determined. If the handshake fails, a secure connection cannot be established.
TLS Handshake Process (4 Steps)
- Client Hello: The browser sends the TLS versions and cipher suites it supports
- Server Hello: Server selects a TLS version and cipher suite, sends its certificate
- Verification: Browser verifies the certificate and creates a pre-master secret
- Completion:Both parties generate the session key and encrypted communication begins
If there is a problem at any step, a "Handshake Failed" error occurs.
Cause 1: Protocol Incompatibility
The browser and server cannot negotiate a common TLS version. Usually the server only supports TLS 1.0/1.1 while the modern browser does not accept them.
Solution
# Check the protocols supported by the server
openssl s_client -connect domain.com:443 -tls1_2
openssl s_client -connect domain.com:443 -tls1_3
# Nginx: TLS 1.2 and 1.3 active
ssl_protocols TLSv1.2 TLSv1.3;
# Apache: TLS 1.2 and 1.3 active
SSLProtocol -all +TLSv1.2 +TLSv1.3
Cause 2: Certificate Chain is Broken
If the intermediate certificate is missing or the order is incorrect, verification will fail during the handshake.
Solution
# Check certificate chain
openssl s_client -connect domain.com:443 -showcerts
# Create fullchain file (correct order)
cat site.crt intermediate.crt > fullchain.pem
#nginx
ssl_certificate /etc/ssl/fullchain.pem;
Cause 3: Expired Certificate
If the certificate has expired, the handshake may fail.
# Check expiry date
openssl s_client -connect domain.com:443 | openssl x509 -noout -dates
# Output:
# notBefore=Jan 15 00:00:00 2026 GMT
# notAfter=Apr 15 23:59:59 2026 GMT
Cause 4: Certificate and Key Mismatch
If the SSL certificate and the private key file do not match, the server cannot verify the signature during the handshake.
# Match check
openssl x509 -noout -modulus -in cert.pem | openssl md5
openssl rsa -noout -modulus -in key.pem | openssl md5
# Both MD5 values must be the same
Cause 5: Firewall or IDS/IPS Interference
A firewall or intrusion detection system may block or disrupt SSL traffic.
Solution
- Verify that port 443 is open:
telnet domain.com 443 - Examine firewall logs for SSL-related blocks
- Check SSL inspection settings in IDS/IPS rules
Cause 6: Server Overload
When the server is under overload, it may not be able to allocate enough resources for the handshake. In particular, RSA key exchange is CPU intensive.
Solution
- Use ECDHE key exchange (faster than RSA)
- Enable SSL session caching
- Use TLS 1.3 (faster handshake — 1-RTT)
# Nginx: Session caching
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;
ssl_session_tickets on;
Debugging Tools
| Tool | Use |
|---|---|
openssl s_client | Detailed handshake information and error messages |
| Wireshark | Analyzing TLS handshake packets |
| SSL Labs | Comprehensive web-based SSL testing |
curl -vvv | Detailed connection information in verbose mode |
| DATASSL SSL Checker | Fast certificate chain check |
Conclusion
SSL/TLS Handshake Failed error may occur for more than one reason. With a systematic approach — first checking certificate validity, then chain, then protocol and cipher compatibility — you can quickly diagnose the problem. Using TLS 1.3 and ECDHE both increases security and shortens handshake time.