Common causes
- Port 443 serves plain HTTP (missing 'listen 443 ssl' or SSL virtual host)
- Certificate or key file paths are wrong, so SSL is not enabled for the site
- The server only allows outdated protocols or ciphers the browser refuses
- A firewall, antivirus or proxy intercepts HTTPS traffic
- No certificate exists for the hostname, so the server has nothing to present
- A wrong system clock on the visitor's device (more often causes certificate date errors)
How to fix it
- Test the handshake from the command line. Run openssl s_client -connect example.com:443 -servername example.com. 'wrong version number' means port 443 is speaking plain HTTP; a certificate chain in the output means SSL works.
- Enable SSL on port 443. In Nginx use listen 443 ssl; with ssl_certificate and ssl_certificate_key paths. In Apache, create a <VirtualHost *:443> block with SSLEngine on and enable mod_ssl (a2enmod ssl).
- Check certificate paths. Confirm the files exist, for example /etc/letsencrypt/live/example.com/fullchain.pem and privkey.pem. Run sudo nginx -t or sudo apachectl configtest to catch errors.
- Use modern protocols. Allow TLS 1.2 and TLS 1.3 only: ssl_protocols TLSv1.2 TLSv1.3; in Nginx or SSLProtocol -all +TLSv1.2 +TLSv1.3 in Apache.
- Rule out local interference. Test from another network or device. If it works elsewhere, check the visitor's antivirus HTTPS scanning, VPN or corporate proxy.
- Check the CDN setting. If you use Cloudflare, make sure the edge certificate is active for the hostname and the DNS record is proxied where you expect.
Minimal Nginx HTTPS server block
server {
listen 443 ssl;
http2 on;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
root /var/www/example.com;
} How to stop it happening again
- Run nginx -t or apachectl configtest before each reload
- Automate certificate renewal with certbot
- Check your HTTPS setup with an SSL checker after changes
- Keep OpenSSL and the web server up to date