Cloudflare's SSL mode is set to Full (Strict) but the origin serves a self-signed or expired certificate, so Cloudflare refuses the origin handshake and Chrome sees the failure.
Cloudflare's SSL mode is set to Full (Strict) but the origin serves a self-signed or expired certificate, so Cloudflare refuses the origin handshake and Chrome sees the failure.
In SSL/TLS → Overview, either install a Cloudflare Origin Certificate on the origin and keep Full (Strict), or temporarily switch to Full while you fix the origin. Never use Flexible with a redirect to HTTPS — that produces a redirect loop.
Cloudflare has its own failure mode, but ERR_SSL_PROTOCOL_ERROR has a wider set of causes. The most common one overall is: The server only offers TLS 1.0 or TLS 1.1, which every current browser has disabled.
Enable TLS 1.2 and TLS 1.3 on the origin and remove the deprecated versions. On nginx set `ssl_protocols TLSv1.2 TLSv1.3;` and reload.
The SSL checker reads the live handshake: protocol versions offered, cipher suites, chain completeness and expiry. If it cannot complete the handshake either, the fault is server-side and not your browser.
Cloudflare's SSL mode is set to Full (Strict) but the origin serves a self-signed or expired certificate, so Cloudflare refuses the origin handshake and Chrome sees the failure.
In SSL/TLS → Overview, either install a Cloudflare Origin Certificate on the origin and keep Full (Strict), or temporarily switch to Full while you fix the origin. Never use Flexible with a redirect to HTTPS — that produces a redirect loop.
Chrome tried to start an encrypted connection and the server answered with something that is not valid TLS. In almost every case the server is offering a protocol version or cipher the browser refuses, the certificate is broken, or something on the network is intercepting the handshake.