---
title: "ERR_SSL_PROTOCOL_ERROR on Nginx: cause and fix"
description: "Nginx serves the wrong certificate chain when ssl_certificate points at the leaf file instead of the fullchain bundle, so the handshake dies before any HTTP…"
canonical: "https://lemwatch.com/errors/err-ssl-protocol-error/in-nginx"
source: "https://lemwatch.com"
---

# ERR_SSL_PROTOCOL_ERROR on Nginx

> Nginx serves the wrong certificate chain when ssl_certificate points at the leaf file instead of the fullchain bundle, so the handshake dies before any HTTP response is written.

## Why it happens on Nginx

 Nginx serves the wrong certificate chain when ssl_certificate points at the leaf file instead of the fullchain bundle, so the handshake dies before any HTTP response is written.

## The fix on Nginx

 Point ssl_certificate at fullchain.pem (not cert.pem), keep ssl_certificate_key on privkey.pem, then run nginx -t && systemctl reload nginx. Set ssl_protocols TLSv1.2 TLSv1.3; anything older is refused by modern Chrome.

## If that didn't fix it

 Nginx has its own failure mode, but ERR_SSL_PROTOCOL_ERROR has a wider set of causes. The most common one overall is: The server only offers TLS 1.0 or TLS 1.1, which every current browser has disabled.

 Enable TLS 1.2 and TLS 1.3 on the origin and remove the deprecated versions. On nginx set `ssl_protocols TLSv1.2 TLSv1.3;` and reload.

## Check your own domain

 The SSL checker reads the live handshake: protocol versions offered, cipher suites, chain completeness and expiry. If it cannot complete the handshake either, the fault is server-side and not your browser.

## Frequently asked questions

### Why does ERR_SSL_PROTOCOL_ERROR happen on Nginx?

 Nginx serves the wrong certificate chain when ssl_certificate points at the leaf file instead of the fullchain bundle, so the handshake dies before any HTTP response is written.

### How do I fix ERR_SSL_PROTOCOL_ERROR on Nginx?

 Point ssl_certificate at fullchain.pem (not cert.pem), keep ssl_certificate_key on privkey.pem, then run nginx -t && systemctl reload nginx. Set ssl_protocols TLSv1.2 TLSv1.3; anything older is refused by modern Chrome.

### What does ERR_SSL_PROTOCOL_ERROR mean?

 Chrome tried to start an encrypted connection and the server answered with something that is not valid TLS. In almost every case the server is offering a protocol version or cipher the browser refuses, the certificate is broken, or something on the network is intercepting the handshake.


## Related

- [All causes of ERR_SSL_PROTOCOL_ERROR](https://lemwatch.com/errors/err-ssl-protocol-error)
- [All website error codes](https://lemwatch.com/errors)
- [ERR_SSL_PROTOCOL_ERROR on Mac](https://lemwatch.com/errors/err-ssl-protocol-error/on-mac)
- [ERR_SSL_PROTOCOL_ERROR on Windows](https://lemwatch.com/errors/err-ssl-protocol-error/on-windows)
- [ERR_SSL_PROTOCOL_ERROR on Chrome](https://lemwatch.com/errors/err-ssl-protocol-error/on-chrome)
- [Free SSL certificate check](https://lemwatch.com/tools/ssl-checker)
- [ERR_SSL_PROTOCOL_ERROR on WordPress](https://lemwatch.com/errors/err-ssl-protocol-error/in-wordpress)
- [ERR_SSL_PROTOCOL_ERROR on Cloudflare](https://lemwatch.com/errors/err-ssl-protocol-error/in-cloudflare)
