Ffile2fix
Sign in Get started

Fix "ERR_SSL_PROTOCOL_ERROR"

This site can't provide a secure connection
example.com sent an invalid response.
ERR_SSL_PROTOCOL_ERROR

This error means the browser and server could not agree on a secure connection. On your own server, the most common cause is port 443 answering with plain HTTP because no SSL virtual host or listen ... ssl line is configured.

Also appears as: Secure Connection Failed. An error occurred during a connection to example.com. SSL received a record that exceeded the maximum permissible length. Error code: SSL_ERROR_RX_RECORD_TOO_LONG · curl: (35) error:0A00010B:SSL routines::wrong version number · net::ERR_SSL_PROTOCOL_ERROR · ERR_SSL_VERSION_OR_CIPHER_MISMATCH

Common causes

  • Port 443 serves plain HTTP (missing 'listen 443 ssl' or SSL virtual host)
  • Certificate or key file paths are wrong, so SSL is not enabled for the site
  • The server only allows outdated protocols or ciphers the browser refuses
  • A firewall, antivirus or proxy intercepts HTTPS traffic
  • No certificate exists for the hostname, so the server has nothing to present
  • A wrong system clock on the visitor's device (more often causes certificate date errors)

How to fix it

  1. Test the handshake from the command line. Run openssl s_client -connect example.com:443 -servername example.com. 'wrong version number' means port 443 is speaking plain HTTP; a certificate chain in the output means SSL works.
  2. Enable SSL on port 443. In Nginx use listen 443 ssl; with ssl_certificate and ssl_certificate_key paths. In Apache, create a <VirtualHost *:443> block with SSLEngine on and enable mod_ssl (a2enmod ssl).
  3. Check certificate paths. Confirm the files exist, for example /etc/letsencrypt/live/example.com/fullchain.pem and privkey.pem. Run sudo nginx -t or sudo apachectl configtest to catch errors.
  4. Use modern protocols. Allow TLS 1.2 and TLS 1.3 only: ssl_protocols TLSv1.2 TLSv1.3; in Nginx or SSLProtocol -all +TLSv1.2 +TLSv1.3 in Apache.
  5. Rule out local interference. Test from another network or device. If it works elsewhere, check the visitor's antivirus HTTPS scanning, VPN or corporate proxy.
  6. Check the CDN setting. If you use Cloudflare, make sure the edge certificate is active for the hostname and the DNS record is proxied where you expect.

Minimal Nginx HTTPS server block

server {
    listen 443 ssl;
    http2 on;
    server_name example.com;
    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    ssl_protocols TLSv1.2 TLSv1.3;
    root /var/www/example.com;
}

How to stop it happening again

  • Run nginx -t or apachectl configtest before each reload
  • Automate certificate renewal with certbot
  • Check your HTTPS setup with an SSL checker after changes
  • Keep OpenSSL and the web server up to date

Frequently asked questions

Is this error on my computer or the website?

If it happens on every device and network, the website's server is misconfigured. If only one device fails, look at that device's clock, antivirus or proxy.

What does 'wrong version number' mean?

The client expected TLS but got a plain HTTP reply. That nearly always means port 443 is not set up for SSL.

Does clearing the SSL state in the browser help?

It can help if a stale session is cached, but it does not fix server misconfiguration. Test with openssl first.