NinjaOps Fixes
/
TLS
TLS Fixes
10 troubleshooting guides — each with the error, why it happens, and copy-paste commands to fix it.
SSL/TLS Handshake Failures: ssl_error_handshake_failure and Friends
— A handshake failure means client and server never agreed on protocol version, cipher, or certificate.
NET::ERR_CERT_AUTHORITY_INVALID — Self-Signed or Missing Chain
— The browser doesn't trust the certificate as presented: it's self-signed, issued by an untrusted CA, or (the sneaky one) the intermediate chain is missing.
SSL_ERROR_RX_RECORD_TOO_LONG — Talking HTTP to a TLS Port (or Vice Versa)
— This error means one side encrypted and the other spoke plain text.
ERR_SSL_VERSION_OR_CIPHER_MISMATCH — No Overlap Between Client and Server
— The client and server share no TLS version or cipher.
curl Error 60: SSL Certificate Problem — Unable to Get Local Issuer Certificate
— curl can't build the chain to a trusted root.
Let's Encrypt DNS-01 Fails: "DNS Problem: NXDOMAIN Looking Up TXT"
— The validation query for _acme-challenge.
Mixed Content: Browser Blocking HTTP Resources on an HTTPS Page
— An HTTPS page loading scripts/images/iframes over plain http:// gets them silently stripped by the browser.
Let's Encrypt http-01 Fails: "Invalid Response From /.well-known/acme-challenge"
— Let's Encrypt fetched your challenge URL and got the wrong answer: another server answered, a proxy intercepted it, or your web server doesn't serve the file.
curl Error 60: SSL Certificate Problem — Self-Signed Certificate
— curl refused the connection because the server's certificate is self-signed (or your internal CA signed it).
curl: Unable to Get Local Issuer Certificate — The Incomplete Chain
— The cert chain is incomplete: the server sent its leaf certificate but not the intermediates needed to build a path to a trusted root.