Cloudflare Error 526: Invalid SSL Certificate (Full-Strict Finds a Problem)

526 fires in Full (strict) mode when your origin's certificate is expired, self-signed, incomplete, or wrong-hostname. The strictness is the point — but each cause has a five-minute fix.

What you'll see

Root causes

Origin cert expired or self-signed

Full (strict) requires a valid CA-signed cert or a Cloudflare Origin CA certificate. openssl s_client -connect origin:443 -servername host | openssl x509 -noout -dates shows the dates.

Incomplete chain or hostname mismatch

Missing intermediate (works in browsers with AIA fetching, fails strict validation) or a cert for the wrong name — openssl ... | openssl x509 -noout -subject -ext subjectAltName.

Fix it

  1. Inspect what your origin actually serves
    openssl s_client -connect <origin-ip>:443 -servername your.domain </dev/null 2>/dev/null | openssl x509 -noout -dates -subject -issuer
  2. Install a Cloudflare Origin CA cert (the clean solution)
    # Cloudflare dashboard → SSL/TLS → Origin Server → Create Certificate; install the cert+key on nginx, keep Full (strict)
  3. Or repair the public cert path (certbot)
    sudo certbot renew --force-renewal -d your.domain && sudo systemctl reload nginx   # check the renewal cron works
  4. Serve the full chain, not just the leaf
    # nginx: ssl_certificate must be fullchain.pem (leaf+intermediates), not cert.pem

Field note

Never 'fix' 526 by switching to Flexible — you'd trade real TLS validation for plaintext hops and likely a redirect loop. Origin CA certs last 15 years and validate only from Cloudflare's edge — ideal for strict mode without renewal juggling.

Common questions

Why do browsers show a padlock but Cloudflare returns 526?

Browsers are lenient (AIA fetches missing intermediates); Cloudflare strict mode validates the served chain as-is. Serve fullchain.pem — that fixes both 526 and odd Android-client failures.

What's the difference between 525 and 526?

525 = handshake failed (protocol/cipher/protocol mismatch); 526 = handshake succeeded but the certificate failed validation (expired/self-signed/wrong name). Debug paths differ accordingly.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.

Get new fixes by email

One short email when new fixes and production templates drop. No spam, unsubscribe anytime.