526 fires in Full (strict) mode when your origin's certificate is expired, self-signed, incomplete, or wrong-hostname. The strictness is the point — but each cause has a five-minute fix.
Full (strict) requires a valid CA-signed cert or a Cloudflare Origin CA certificate. openssl s_client -connect origin:443 -servername host | openssl x509 -noout -dates shows the dates.
Missing intermediate (works in browsers with AIA fetching, fails strict validation) or a cert for the wrong name — openssl ... | openssl x509 -noout -subject -ext subjectAltName.
openssl s_client -connect <origin-ip>:443 -servername your.domain </dev/null 2>/dev/null | openssl x509 -noout -dates -subject -issuer
# Cloudflare dashboard → SSL/TLS → Origin Server → Create Certificate; install the cert+key on nginx, keep Full (strict)
sudo certbot renew --force-renewal -d your.domain && sudo systemctl reload nginx # check the renewal cron works
# nginx: ssl_certificate must be fullchain.pem (leaf+intermediates), not cert.pem
Never 'fix' 526 by switching to Flexible — you'd trade real TLS validation for plaintext hops and likely a redirect loop. Origin CA certs last 15 years and validate only from Cloudflare's edge — ideal for strict mode without renewal juggling.
Browsers are lenient (AIA fetches missing intermediates); Cloudflare strict mode validates the served chain as-is. Serve fullchain.pem — that fixes both 526 and odd Android-client failures.
525 = handshake failed (protocol/cipher/protocol mismatch); 526 = handshake succeeded but the certificate failed validation (expired/self-signed/wrong name). Debug paths differ accordingly.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.
One short email when new fixes and production templates drop. No spam, unsubscribe anytime.