SSL Handshake Failed: It Is Usually the Chain

Symptom

Some clients work; others get handshake failures or "certificate unknown".

Root cause

Full chain not served (only the leaf cert), or SNI/TLS version mismatch.

Fix, in order

1. Serve the fullchain, not just the certssl_certificate /etc/letsencrypt/live/d/fullchain.pem;
2. Verify from outsideopenssl s_client -connect host:443 -servername d < /dev/null 2>/dev/null | head
3. Check what you actually servecurl -vI https://d 2>&1 | grep -E "SSL|issuer|subject"

Prevent it coming back

Automated renewal + external chain validation monitoring.

Run it on clean infra

Spinning up a fresh box to reproduce or escape this error?

Managed cloud hosting

Related

Cloud & DevOps tool comparisons · Hardware build guides

NinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.

Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog