cloudflare ssl handshake failure new subdomain
For admins and agents running sites behind Cloudflare. Use when new subdomains fail handshakes. Not for origin outages.
Fix Cloudflare SSL handshake failure on a new subdomain
TL;DR
Handshake failures on a new subdomain usually mean the edge certificate does not cover it yet, or the origin SSL mode mismatches. Check the edge certificate coverage in Cloudflare, then set the SSL mode to match what your origin actually serves. New subdomains need a few minutes for the universal certificate.
The error
SSL handshake failure
ERR_SSL_VERSION_OR_CIPHER_MISMATCH on new subdomain behind Cloudflare.Use this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=cloudflare ssl handshake failure new subdomain"Fix it
Step 1: Check edge certificate coverage
Cloudflare dashboard -> SSL/TLS -> Edge Certificates; confirm the universal cert covers the new subdomain.Expected: The subdomain is listed or the wildcard covers it.
Step 2: Wait for universal cert issuance if missing
If the cert is still issuing, wait a few minutes and recheck.Expected: The certificate shows active for the subdomain.
Step 3: Match the SSL mode to your origin
Set the encryption mode to Full (strict) only if your origin serves a valid cert; otherwise use Full.Expected: The mode matches what the origin actually presents.
Step 4: Verify the origin certificate
Check the origin's own certificate validity directly, bypassing Cloudflare.Expected: The origin serves a valid, unexpired certificate.
Step 5: Test the handshake
Reload the subdomain and check the certificate chain.Expected: The handshake completes with a valid chain.
When this applies
- New Cloudflare subdomains fail the SSL handshake
- The apex works but the subdomain does not
- You just changed the SSL mode
When it doesn't
- All subdomains fail (check the universal certificate status)
- The origin is down (check the origin directly)
- The error is a redirect loop (check the SSL mode and origin config)
Compatibility
Cloudflare proxy with Universal SSL. Origin servers vary.
Variant phrasings
cloudflare subdomain ssl error
Same failure. Coverage plus SSL mode covers nearly every case.
errsslversionorcipher_mismatch cloudflare
This specific error often means the edge has no valid cert for the host yet.
cloudflare full strict handshake failure
Full (strict) fails when the origin cert is invalid or self-signed. Use Full or fix the origin cert.
Why it happens
Cloudflare terminates TLS at the edge with its own certificate, then connects to your origin. A new subdomain needs edge certificate coverage, which takes minutes to issue, and the origin connection needs an SSL mode matching what the origin serves. Either gap breaks the handshake.
Edge cases
- Deeply nested subdomains may exceed universal cert coverage; check the hostname limit
- Origin CA certificates from Cloudflare only work with proxied traffic; direct origin hits fail
- HSTS on the origin can lock browsers into HTTPS during debugging; test in a fresh profile
If it still fails
- Verify from multiple networks; one network's cache is not the internet's state.
- Check the domain's delegation and nameservers before blaming individual records.
- Wait out one full TTL after a fix before declaring it still broken.
- Keep a known-good dig output to diff against during the next incident.
- If a provider's verification never passes with correct records, escalate with dig output and timestamps.
Prevention
- Lower TTLs a day before any planned DNS change.
- Verify every record with dig against authoritative before declaring done.
- Monitor certificate and domain expiry with alerts, not memory.
- Keep DNS change history; most outages are a bad edit, not propagation.
- Test verification flows in staging with a throwaway subdomain.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_6CNsW3SSdtFWetyslVTgYw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.