How to fix ERR_SSL_PROTOCOL_ERROR

The browser and server could not agree on a secure connection at all. Usually HTTPS is not set up on that port, or the configuration is broken.

1–2 minutes
Close-up of light travelling through fibre optic strands

ERR_SSL_PROTOCOL_ERROR (“this site can’t provide a secure connection”) means the HTTPS handshake failed before any certificate check. Typically the server is not really speaking HTTPS on port 443, or its TLS settings are broken or outdated.

If you are visiting the site

  • Check your device’s date and time.
  • Clear the browser’s cache and try a private window.
  • Try another browser or network; security software that inspects HTTPS can cause it.

If you run the site

1. Test the handshake

echo | openssl s_client -connect example.com:443 -servername example.com

wrong version number or no peer certificate available usually means plain HTTP is being served on port 443.

2. Check the listen line

In Nginx, an HTTPS site needs ssl on its listen line:

listen 443 ssl;
listen [::]:443 ssl;

listen 443; without ssl serves plain HTTP on the HTTPS port, which causes exactly this error. Then:

sudo nginx -t
sudo systemctl reload nginx

3. Check a certificate exists for the name

If no site on the server has a certificate for the requested name, the server may fail the handshake. Issue one with Let’s Encrypt.

4. Outdated TLS settings

Allow modern versions only:

ssl_protocols TLSv1.2 TLSv1.3;

Very old settings, or a cipher list copied from an old guide, can leave nothing that modern browsers accept.

See also Your connection is not private, which is a certificate problem rather than a handshake problem.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.