Secure connection and certificate errors
ERR_SSL_VERSION_OR_CIPHER_MISMATCH
The browser and server share no secure way to connect.
Quick answer
The website uses old or unusual security settings that modern browsers no longer accept. Visitors cannot fix this; the website must update its HTTPS configuration.
When to wait: Waiting does not help; the website must update.
If you are visiting the website
- Update your browser A current browser supports the newest secure methods. Update and restart it, then reload the page.
- Windows
- In Chrome: More (three dots) > Help > About Google Chrome. Chrome checks for updates; click Relaunch when asked.
- macOS
- In Chrome: More (three dots) > Help > About Google Chrome, then Relaunch. For Safari, update macOS in System Settings > General > Software Update.
- Android
- Open the Play Store, search for your browser and tap Update if shown.
- iPhone and iPad (iOS)
- Open the App Store, tap your profile picture and update your browser if listed. Safari updates come with iOS in Settings > General > Software Update.
- Try another browser If a second up-to-date browser also fails, the website is almost certainly the cause. If only one browser fails, that browser or something added to it is involved.
- Test security software briefly Antivirus HTTPS scanning sits between you and the site and must support modern encryption too. Pause the scanning for one reload, then turn it back on and update the program.
- Try another network Old company proxies or filters can also lack modern encryption. Test on mobile data to rule that out.
- Tell the website owner If every up-to-date browser fails on every network, the site uses outdated security settings. Contact it through another channel and quote the error code.
If you run the website
- Enable TLS 1.2 and TLS 1.3 In nginx use
ssl_protocols TLSv1.2 TLSv1.3;. Google's Chrome help advises servers to support TLS 1.3 with the TLS_AES_128_GCM_SHA256 cipher suite. - Remove outdated cipher lists Old configurations copied from forums or old examples may only list ciphers modern browsers have dropped, such as RC4 or 3DES. Use your server's current recommended defaults or a maintained configuration generator.
- Test each protocol version Run
openssl s_client -connect example.com:443 -servername example.com -tls1_2, then the same with-tls1_3. A failed handshake on both shows the server offers no modern option. - Check SNI and the certificate per name If the server has no matching site for the requested name, it may answer with an odd default setup. Make sure every hostname has its own server block and certificate.
- Check older appliances and load balancers Encryption often ends at a load balancer, firewall or CDN, not at the web server. Update its TLS settings or firmware too, then test again from outside.
What "version or cipher mismatch" means
Before any page loads, browser and server must agree on a TLS version (the edition of the security rules) and a cipher (the exact lock they use). If they share no option, the connection ends here.
Modern browsers have dropped old, weak options on purpose. A server that only offers those options cannot be reached.
Is it the website or me?
If an up-to-date browser on a normal home or mobile network fails, the website is the cause. Visitors cannot fix it.
If only an old device fails, that device may be too old for modern encryption. Updating the system or using a newer device helps.
How it differs from ERR_SSL_PROTOCOL_ERROR
ERR_SSL_PROTOCOL_ERROR means the handshake broke in some unexpected way. This error is more specific: both sides spoke correctly but had nothing in common.
Firefox shows the same situation as SSL_ERROR_NO_CYPHER_OVERLAP.
Common questions
Can I turn on old security settings in my browser to get in?
Do not try. Those options were removed because they are weak. The website needs to update its settings.
Why does the site work on my old computer but not my new one?
Old software still accepts outdated methods that new software rejects. The site is relying on weak encryption.
Is my data at risk?
No data was sent, because no secure connection was set up. The error protects you from using weak encryption.
How long does it take an owner to fix this?
On a server they control, changing the TLS settings and reloading is usually quick. Older hardware or hosting panels can take longer.
Likely causes
- Common The server only supports outdated TLS versions or ciphers. (Website side)
- Sometimes The certificate or HTTPS setup does not match this name. (Website side)
Is the website down? Check it now
One measurement point. Results explain what we saw, not a worldwide verdict.
Related messages
Sources
- Chromium source: net/base/net_error_list.h
- Google Chrome Help: Get help with common error messages in Chrome
- MDN: Transport Layer Security (TLS)
- nginx: Module ngx_http_ssl_module
- OpenSSL: s_client manual
- Google Chrome Help: Update Google Chrome
Last reviewed: