Cloudflare errors

Cloudflare error 526: Invalid SSL certificate

Cloudflare could not verify the website server's certificate.

Quick answer

A 526 means Cloudflare is set to strictly check the real server's certificate, and that check failed. The certificate may be expired, self-signed, or for another name.

When to wait: Waiting does not help; the certificate must be fixed.

If you are visiting the website

  1. Reload once later A 526 usually stays until the owner replaces the certificate. Reload once later in the day; repeated reloading will not change it.
  2. Check the site from outside your network Run a check on CheckWebsiteNow or open the site on mobile data. If it fails everywhere, the problem is the website's certificate, not your device.
  3. Write down the Ray ID and the time The error page shows a 'Cloudflare Ray ID' (a code for your exact request) at the bottom. Note it with the time and time zone.
  4. Tell the website owner Contact the website through another channel (email or social media). Mention 'Cloudflare 526, invalid SSL certificate', the Ray ID and the time, because an expired certificate is often all it takes.

If you run the website

  1. Read the certificate your server sends Run openssl s_client -connect ORIGIN_IP:443 -servername example.com and pipe the output into openssl x509 -noout -dates -subject -issuer. You see the expiry date, the name the certificate covers and who issued it.
  2. Renew an expired certificate With Let's Encrypt, sudo certbot certificates lists your certificates and their expiry. Run sudo certbot renew --dry-run to test, then sudo certbot renew, and reload the web server afterwards.
  3. Cover every hostname The certificate must name the requested hostname in its Common Name or Subject Alternative Name (the list of names it is valid for). A certificate for example.com does not cover www.example.com unless both are listed.
  4. Send the full certificate chain Cloudflare needs your certificate plus the intermediate certificates. In nginx, the ssl_certificate file must contain your certificate first, followed by the intermediates.
  5. Or use a Cloudflare Origin CA certificate Create one under SSL/TLS, Origin Server, Create Certificate, and install it on your server. Cloudflare trusts it in Full (strict) mode, but browsers do not trust it without Cloudflare in front.
  6. Replace self-signed certificates A self-signed certificate (one you made yourself) fails the strict check. Replace it with a trusted one, or add it to Cloudflare's Custom Origin Trust Store if you must keep it.
  7. Make renewal automatic Check that the certbot timer or cron job runs, for example with systemctl list-timers. Add a deploy hook such as --deploy-hook "systemctl reload nginx" so the new certificate is actually used.

Is it the website or me?

It is the website. Cloudflare (a service between visitors and many websites) checked the certificate on the website's own server and found it invalid.

Your clock, browser and antivirus play no role in this check. Only the owner can fix it.

What the strict check looks at

In Full (strict) mode, Cloudflare only accepts an origin certificate that has not expired and was issued by a public certificate authority or by Cloudflare's Origin CA. It must also contain the requested hostname.

The chain must be complete and the certificate must not be revoked. If any of these fail, visitors see a 526.

Why switching to 'Full' is not a real fix

Cloudflare lists switching from Full (strict) to Full as a quick way to remove the error. Full mode skips the certificate check, so Cloudflare would also accept a forged or wrong certificate.

Use it at most as a short emergency measure while you renew. Then switch back to Full (strict).

For developers: what happens technically

Cloudflare completes the TLS handshake with the origin, then validates the presented chain, the validity dates and the hostname. Validation failure in strict mode returns 526, while a failed handshake returns 525.

An expired Let's Encrypt certificate after a broken renewal job is a classic cause. Monitoring the expiry date prevents it.

Common questions

Is it safe for me to use this site?

You cannot reach the site while the 526 is shown, so no data goes anywhere. Your link to Cloudflare is still encrypted; wait until the owner fixes the certificate.

Why did it break suddenly when nothing changed?

Certificates expire on a fixed date. If automatic renewal stopped working, the site breaks on that day without any visible change.

Should I switch Cloudflare to Full mode to stop the error?

Only as a brief emergency measure. Full mode stops checking the certificate, which removes protection against a fake server. Renew or replace the certificate and return to Full (strict).

Is Cloudflare down?

Usually not. Cloudflare is working and is protecting visitors by refusing a certificate it cannot trust.

Likely causes

  • Common The certificate on the server is expired. (Website side)
  • Sometimes The certificate is self-signed or does not include this domain. (Website side)

What to avoid

  • Do not lower security settings as a permanent fix; replace the certificate instead.
  • Do not leave the SSL mode on Full or Flexible to hide a 526; renew or replace the certificate and use Full (strict).

Is the website down? Check it now

One measurement point. Results explain what we saw, not a worldwide verdict.

Sources

Last reviewed: