Secure connection and certificate errors

ERR_SSL_PROTOCOL_ERROR

The secure connection could not be set up correctly.

Quick answer

The browser and server started setting up HTTPS, but something did not follow the rules. Often the server is not really serving HTTPS on that port, or a proxy or security tool interferes.

When to wait: Waiting rarely helps.

If you are visiting the website

  1. Check http versus https If you typed https:// for an address that only offers plain http, such as some router pages or local test servers, this error appears. Check the exact address and port you were given.
  2. Check your device's date and time A wrong clock can break secure setup. Turn on automatic time and reload.
    Windows
    Start > Settings > Time & language > Date & time. Turn on "Set time automatically".
    macOS
    Apple menu > System Settings > General > Date & Time. Turn on "Set time and date automatically".
    Android
    Settings > System > Date & time. Turn on "Set time automatically".
    iPhone and iPad (iOS)
    Settings > General > Date & Time. Turn on "Set Automatically".
  3. Try a private window Open the site in a private (incognito) window. Extensions are usually off there. If it works, turn your extensions off one by one to find the cause.
  4. Test your security software and VPN Antivirus HTTPS scanning, a VPN or a filtering app can break the secure handshake. Pause one of them for a single test reload, then turn it back on.
  5. Check proxy settings A leftover proxy can garble secure connections. If you do not need a proxy, make sure none is set.
    Windows
    Start > Settings > Network & internet > Proxy. Turn off any manual proxy you did not set up on purpose.
    macOS
    Apple menu > System Settings > Network > select your network > Details > Proxies. Turn off proxies you do not need.
  6. Try another network Switch between Wi-Fi and mobile data. If the site works on the other network, a firewall or filter on the first one is interfering.

If you run the website

  1. Confirm port 443 really speaks TLS Run curl -v https://example.com. If the handshake fails at once, the port may be serving plain HTTP. In Firefox this often shows as SSL_ERROR_RX_RECORD_TOO_LONG. In nginx the listen line needs ssl, for example listen 443 ssl;.
  2. Inspect the handshake Run openssl s_client -connect example.com:443 -servername example.com. Look for the certificate, the protocol version and any alert. Compare with the server error log at the same time.
  3. Allow modern protocols Make sure TLS 1.2 and TLS 1.3 are enabled. In nginx this is ssl_protocols TLSv1.2 TLSv1.3;, which is the default in current versions. Test with sudo nginx -t, then reload with sudo nginx -s reload.
  4. Match CDN and origin settings Behind Cloudflare, Full or Full (strict) mode needs a working HTTPS server on port 443 at the origin. Flexible mode connects over plain HTTP instead. Pick one setup and configure both sides the same way.
  5. Check certificate and key files A certificate that does not belong to the private key, or an unreadable file, can make the server fail the handshake. Check the error log after every change.

Is it the website or me?

Open the same address on a phone using mobile data. If it fails there too, the website's HTTPS setup is broken.

If it works on the phone, look at your computer: extensions, antivirus HTTPS scanning, a VPN or an old proxy setting.

How it differs from certificate errors

Certificate errors show a warning page about who the site is. This error happens earlier, while browser and server are still agreeing how to encrypt.

There is usually no way to continue. That protects you, because no secure channel exists yet.

For developers: common technical causes

The classic case is plain HTTP answering on port 443. The browser expects a TLS record and receives an HTTP response instead.

Other causes are broken TLS on a load balancer, a middlebox that changes traffic, or protocol versions that do not overlap.

Common questions

Will clearing my browser data fix ERR_SSL_PROTOCOL_ERROR?

Rarely. The handshake happens fresh on each connection. Clearing data for one site does no harm, but test extensions, security software and the network first.

Why does the site open on my phone but not my computer?

Then the website is probably fine. Something on the computer, such as an extension, antivirus or proxy, is breaking the secure connection.

Should I turn off my antivirus to open the site?

Only pause its HTTPS scanning for one quick test, then turn it back on. If that was the cause, update the program or report it to the vendor.

Is ERR_SSL_PROTOCOL_ERROR dangerous?

Not in itself. The browser stopped before sending anything. It does mean you cannot use the site securely until the cause is fixed.

Likely causes

  • Common The server has no proper HTTPS setup on port 443. (Website side)
  • Sometimes Security software, a VPN or proxy interferes. (Your side)

What to avoid

  • Do not turn off your antivirus permanently.

Is the website down? Check it now

One measurement point. Results explain what we saw, not a worldwide verdict.

Sources

Last reviewed: