[{"data":1,"prerenderedAt":2137},["ShallowReactive",2],{"content-query-kybquSlpTu":3,"content-query-W4RtfFQaoh":1909,"content-query-yP1cWMns5L":1934,"content-query-eJ9XWy0CGH":1938,"content-query-M5aWdXgQKx":1951,"content-query-UP87PRcOMw":1958,"content-query-7VgBfxLOWV":1962,"content-query-Z6fTkbgt1D":1984,"content-query-9giMhwHrGj":1997,"content-query-j8GGVgf9na":2004,"content-query-IVhcXRs1sR":2017,"content-query-1mvwAKmUBq":2027,"content-query-G03kJtQzJS":2052,"content-query-No6iPTj4EO":2074,"content-query-zRSmsuVl55":2084,"content-query-MsdmgXewTK":2088,"content-query-BMhIInEJl2":2095},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"head":10,"intro":12,"type":13,"layout":14,"level":15,"section":5,"order":16,"tags":17,"body":24,"_type":1902,"_id":1903,"_source":1904,"_file":1905,"_stem":1906,"_extension":1907,"sitemap":1908},"/docs/webhooks/tls-ssl-errors","webhooks",false,"","Fix TLS/SSL handshake errors: unsupported protocol, wrong version number, handshake failure","What each common TLS/SSL handshake error means — handshake failure, protocol version, unsupported protocol, certificate verify failed — and how to fix it.",{"title":11},"Fix TLS/SSL Handshake Errors","Most TLS errors come down to one thing: the two sides couldn't agree on a protocol version, cipher or certificate. This page lists the exact error strings curl, OpenSSL, Python, Node.js, Java, Go and browsers print — what each means, and how Webhook Relay accepts legacy senders and delivers across the gap.","tutorial","doc","Intermediate",11,[18,19,20,21,22,23],"TLS","SSL","Handshake","Troubleshooting","Legacy TLS","Webhooks",{"type":25,"children":26,"toc":1871},"root",[27,43,63,84,91,248,258,263,337,347,387,397,417,487,496,505,515,527,541,550,559,569,581,618,627,660,685,697,702,748,765,804,816,862,879,896,907,912,999,1008,1017,1029,1043,1052,1061,1073,1096,1129,1146,1167,1179,1323,1332,1347,1353,1372,1379,1398,1410,1481,1490,1495,1552,1558,1596,1604,1609,1615,1623,1669,1677,1712,1718,1724,1750,1756,1775,1781,1799,1805,1822,1828,1865],{"type":28,"tag":29,"props":30,"children":31},"element","p",{},[32,35,41],{"type":33,"value":34},"text","Almost every TLS/SSL handshake error means the same thing underneath: ",{"type":28,"tag":36,"props":37,"children":38},"strong",{},[39],{"type":33,"value":40},"the client and the server could not agree on a protocol version or cipher suite",{"type":33,"value":42},". One side offered only modern TLS 1.2/1.3; the other offered only legacy TLS 1.0/1.1 (or a weak cipher) — and there was no overlap, so the handshake was aborted.",{"type":28,"tag":29,"props":44,"children":45},{},[46,48,54,56,61],{"type":33,"value":47},"This happens constantly when webhooks cross a boundary between ",{"type":28,"tag":49,"props":50,"children":51},"em",{},[52],{"type":33,"value":53},"modern",{"type":33,"value":55}," and ",{"type":28,"tag":49,"props":57,"children":58},{},[59],{"type":33,"value":60},"legacy",{"type":33,"value":62}," infrastructure: a new SaaS sender that speaks only TLS 1.3 trying to reach an old on-prem appliance, or a hardened endpoint that has disabled TLS 1.0/1.1 rejecting an older client that can't go higher.",{"type":28,"tag":29,"props":64,"children":65},{},[66,68,73,75,82],{"type":33,"value":67},"This page is a reference for the ",{"type":28,"tag":36,"props":69,"children":70},{},[71],{"type":33,"value":72},"exact error strings",{"type":33,"value":74}," different tools print, what each one means, and how to fix it — including how ",{"type":28,"tag":76,"props":77,"children":79},"a",{"href":78},"#how-webhook-relay-bridges-the-gap",[80],{"type":33,"value":81},"Webhook Relay's TLS compatibility",{"type":33,"value":83}," lets a legacy sender deliver webhooks that a modern endpoint would refuse, and lets you deliver to destinations with non-standard certificates.",{"type":28,"tag":85,"props":86,"children":88},"h2",{"id":87},"quick-diagnosis",[89],{"type":33,"value":90},"Quick diagnosis",{"type":28,"tag":92,"props":93,"children":94},"table",{},[95,114],{"type":28,"tag":96,"props":97,"children":98},"thead",{},[99],{"type":28,"tag":100,"props":101,"children":102},"tr",{},[103,109],{"type":28,"tag":104,"props":105,"children":106},"th",{},[107],{"type":33,"value":108},"What you see",{"type":28,"tag":104,"props":110,"children":111},{},[112],{"type":33,"value":113},"What it usually means",{"type":28,"tag":115,"props":116,"children":117},"tbody",{},[118,152,176,193,217],{"type":28,"tag":100,"props":119,"children":120},{},[121,147],{"type":28,"tag":122,"props":123,"children":124},"td",{},[125,132,134,140,141],{"type":28,"tag":126,"props":127,"children":129},"code",{"className":128},[],[130],{"type":33,"value":131},"unsupported protocol",{"type":33,"value":133}," / ",{"type":28,"tag":126,"props":135,"children":137},{"className":136},[],[138],{"type":33,"value":139},"protocol_version",{"type":33,"value":133},{"type":28,"tag":126,"props":142,"children":144},{"className":143},[],[145],{"type":33,"value":146},"ERR_SSL_VERSION_OR_CIPHER_MISMATCH",{"type":28,"tag":122,"props":148,"children":149},{},[150],{"type":33,"value":151},"One side requires a TLS version the other has disabled (e.g. server only allows TLS 1.2+, client only offers TLS 1.0/1.1, or vice-versa).",{"type":28,"tag":100,"props":153,"children":154},{},[155,171],{"type":28,"tag":122,"props":156,"children":157},{},[158,164,165],{"type":28,"tag":126,"props":159,"children":161},{"className":160},[],[162],{"type":33,"value":163},"sslv3 alert handshake failure",{"type":33,"value":133},{"type":28,"tag":126,"props":166,"children":168},{"className":167},[],[169],{"type":33,"value":170},"handshake_failure",{"type":28,"tag":122,"props":172,"children":173},{},[174],{"type":33,"value":175},"No shared cipher suite, a missing client certificate, or a rejected protocol version.",{"type":28,"tag":100,"props":177,"children":178},{},[179,188],{"type":28,"tag":122,"props":180,"children":181},{},[182],{"type":28,"tag":126,"props":183,"children":185},{"className":184},[],[186],{"type":33,"value":187},"wrong version number",{"type":28,"tag":122,"props":189,"children":190},{},[191],{"type":33,"value":192},"One side is speaking plain HTTP to an HTTPS port (or TLS to a plaintext port) — often not a version problem at all.",{"type":28,"tag":100,"props":194,"children":195},{},[196,212],{"type":28,"tag":122,"props":197,"children":198},{},[199,205,206],{"type":28,"tag":126,"props":200,"children":202},{"className":201},[],[203],{"type":33,"value":204},"dh key too small",{"type":33,"value":133},{"type":28,"tag":126,"props":207,"children":209},{"className":208},[],[210],{"type":33,"value":211},"no cipher overlap",{"type":28,"tag":122,"props":213,"children":214},{},[215],{"type":33,"value":216},"The server's certificate or DH parameters use a cipher the modern client refuses.",{"type":28,"tag":100,"props":218,"children":219},{},[220,243],{"type":28,"tag":122,"props":221,"children":222},{},[223,229,230,236,237],{"type":28,"tag":126,"props":224,"children":226},{"className":225},[],[227],{"type":33,"value":228},"certificate verify failed",{"type":33,"value":133},{"type":28,"tag":126,"props":231,"children":233},{"className":232},[],[234],{"type":33,"value":235},"self-signed certificate",{"type":33,"value":133},{"type":28,"tag":126,"props":238,"children":240},{"className":239},[],[241],{"type":33,"value":242},"unable to verify the first certificate",{"type":28,"tag":122,"props":244,"children":245},{},[246],{"type":33,"value":247},"The version is fine, but the endpoint's certificate isn't trusted by a public CA (self-signed, internal CA, or incomplete chain).",{"type":28,"tag":85,"props":249,"children":251},{"id":250},"error0a000102ssl-routinesunsupported-protocol",[252],{"type":28,"tag":126,"props":253,"children":255},{"className":254},[],[256],{"type":33,"value":257},"error:0A000102:SSL routines::unsupported protocol",{"type":28,"tag":29,"props":259,"children":260},{},[261],{"type":33,"value":262},"The OpenSSL 3.x \"no common protocol version\" error. You'll also see it wrapped by curl and Node.js:",{"type":28,"tag":264,"props":265,"children":268},"pre",{"className":266,"code":267,"language":33,"meta":7,"style":7},"language-text shiki shiki-themes github-dark","curl: (35) error:0A000102:SSL routines::unsupported protocol\n\n# OpenSSL 1.1.x phrased it as:\nerror:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol\n\n# Node.js:\nError: write EPROTO ... error:0A000102:SSL routines::unsupported protocol\n",[269],{"type":28,"tag":126,"props":270,"children":271},{"__ignoreMap":7},[272,283,293,302,311,319,328],{"type":28,"tag":273,"props":274,"children":277},"span",{"class":275,"line":276},"line",1,[278],{"type":28,"tag":273,"props":279,"children":280},{},[281],{"type":33,"value":282},"curl: (35) error:0A000102:SSL routines::unsupported protocol\n",{"type":28,"tag":273,"props":284,"children":286},{"class":275,"line":285},2,[287],{"type":28,"tag":273,"props":288,"children":290},{"emptyLinePlaceholder":289},true,[291],{"type":33,"value":292},"\n",{"type":28,"tag":273,"props":294,"children":296},{"class":275,"line":295},3,[297],{"type":28,"tag":273,"props":298,"children":299},{},[300],{"type":33,"value":301},"# OpenSSL 1.1.x phrased it as:\n",{"type":28,"tag":273,"props":303,"children":305},{"class":275,"line":304},4,[306],{"type":28,"tag":273,"props":307,"children":308},{},[309],{"type":33,"value":310},"error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol\n",{"type":28,"tag":273,"props":312,"children":314},{"class":275,"line":313},5,[315],{"type":28,"tag":273,"props":316,"children":317},{"emptyLinePlaceholder":289},[318],{"type":33,"value":292},{"type":28,"tag":273,"props":320,"children":322},{"class":275,"line":321},6,[323],{"type":28,"tag":273,"props":324,"children":325},{},[326],{"type":33,"value":327},"# Node.js:\n",{"type":28,"tag":273,"props":329,"children":331},{"class":275,"line":330},7,[332],{"type":28,"tag":273,"props":333,"children":334},{},[335],{"type":33,"value":336},"Error: write EPROTO ... error:0A000102:SSL routines::unsupported protocol\n",{"type":28,"tag":29,"props":338,"children":339},{},[340,345],{"type":28,"tag":36,"props":341,"children":342},{},[343],{"type":33,"value":344},"What it means:",{"type":33,"value":346}," the client and server share no enabled TLS protocol version. The most common cause today is a modern client (OpenSSL 3, which disables TLS 1.0/1.1 by default) connecting to a server that only speaks those old versions.",{"type":28,"tag":29,"props":348,"children":349},{},[350,355,357,363,365,371,373,378,380,385],{"type":28,"tag":36,"props":351,"children":352},{},[353],{"type":33,"value":354},"Fix on your side:",{"type":33,"value":356}," upgrade the server to TLS 1.2/1.3, or — if you genuinely must talk to a legacy box — explicitly re-enable an older protocol on the client (",{"type":28,"tag":126,"props":358,"children":360},{"className":359},[],[361],{"type":33,"value":362},"curl --tlsv1.0",{"type":33,"value":364},", or an OpenSSL config with ",{"type":28,"tag":126,"props":366,"children":368},{"className":367},[],[369],{"type":33,"value":370},"MinProtocol = TLSv1",{"type":33,"value":372},"). If the legacy system is the one ",{"type":28,"tag":49,"props":374,"children":375},{},[376],{"type":33,"value":377},"sending",{"type":33,"value":379}," you webhooks, point it at a ",{"type":28,"tag":76,"props":381,"children":382},{"href":78},[383],{"type":33,"value":384},"Webhook Relay input with legacy TLS enabled",{"type":33,"value":386}," instead of lowering TLS on everything else.",{"type":28,"tag":85,"props":388,"children":390},{"id":389},"error14094410ssl-routinesssl3_read_bytessslv3-alert-handshake-failure",[391],{"type":28,"tag":126,"props":392,"children":394},{"className":393},[],[395],{"type":33,"value":396},"error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure",{"type":28,"tag":29,"props":398,"children":399},{},[400,402,408,410,415],{"type":33,"value":401},"Despite the ",{"type":28,"tag":126,"props":403,"children":405},{"className":404},[],[406],{"type":33,"value":407},"sslv3",{"type":33,"value":409}," label, this rarely involves SSLv3 — it's a generic ",{"type":28,"tag":36,"props":411,"children":412},{},[413],{"type":33,"value":414},"handshake failure alert (alert number 40)",{"type":33,"value":416}," from the peer.",{"type":28,"tag":264,"props":418,"children":420},{"className":266,"code":419,"language":33,"meta":7,"style":7},"# OpenSSL / curl\ncurl: (35) error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure\n\n# Python\nssl.SSLError: [SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:1007)\n\n# OpenSSL 3.x\nerror:0A000410:SSL routines::sslv3 alert handshake failure\n",[421],{"type":28,"tag":126,"props":422,"children":423},{"__ignoreMap":7},[424,432,440,447,455,463,470,478],{"type":28,"tag":273,"props":425,"children":426},{"class":275,"line":276},[427],{"type":28,"tag":273,"props":428,"children":429},{},[430],{"type":33,"value":431},"# OpenSSL / curl\n",{"type":28,"tag":273,"props":433,"children":434},{"class":275,"line":285},[435],{"type":28,"tag":273,"props":436,"children":437},{},[438],{"type":33,"value":439},"curl: (35) error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure\n",{"type":28,"tag":273,"props":441,"children":442},{"class":275,"line":295},[443],{"type":28,"tag":273,"props":444,"children":445},{"emptyLinePlaceholder":289},[446],{"type":33,"value":292},{"type":28,"tag":273,"props":448,"children":449},{"class":275,"line":304},[450],{"type":28,"tag":273,"props":451,"children":452},{},[453],{"type":33,"value":454},"# Python\n",{"type":28,"tag":273,"props":456,"children":457},{"class":275,"line":313},[458],{"type":28,"tag":273,"props":459,"children":460},{},[461],{"type":33,"value":462},"ssl.SSLError: [SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:1007)\n",{"type":28,"tag":273,"props":464,"children":465},{"class":275,"line":321},[466],{"type":28,"tag":273,"props":467,"children":468},{"emptyLinePlaceholder":289},[469],{"type":33,"value":292},{"type":28,"tag":273,"props":471,"children":472},{"class":275,"line":330},[473],{"type":28,"tag":273,"props":474,"children":475},{},[476],{"type":33,"value":477},"# OpenSSL 3.x\n",{"type":28,"tag":273,"props":479,"children":481},{"class":275,"line":480},8,[482],{"type":28,"tag":273,"props":483,"children":484},{},[485],{"type":33,"value":486},"error:0A000410:SSL routines::sslv3 alert handshake failure\n",{"type":28,"tag":29,"props":488,"children":489},{},[490,494],{"type":28,"tag":36,"props":491,"children":492},{},[493],{"type":33,"value":344},{"type":33,"value":495}," the server rejected the handshake. Common causes are no shared cipher suite, the server requiring a client certificate you didn't present, or the server refusing the protocol version the client offered.",{"type":28,"tag":29,"props":497,"children":498},{},[499,503],{"type":28,"tag":36,"props":500,"children":501},{},[502],{"type":33,"value":354},{"type":33,"value":504}," confirm the client and server share at least one cipher suite and TLS version, and supply a client certificate if the endpoint requires mutual TLS.",{"type":28,"tag":85,"props":506,"children":508},{"id":507},"error1409442essl-routinesssl3_read_bytestlsv1-alert-protocol-version",[509],{"type":28,"tag":126,"props":510,"children":512},{"className":511},[],[513],{"type":33,"value":514},"error:1409442E:SSL routines:ssl3_read_bytes:tlsv1 alert protocol version",{"type":28,"tag":29,"props":516,"children":517},{},[518,520,525],{"type":33,"value":519},"The peer sent a ",{"type":28,"tag":36,"props":521,"children":522},{},[523],{"type":33,"value":524},"protocol_version alert (alert number 70)",{"type":33,"value":526}," — it explicitly rejected the TLS version you offered.",{"type":28,"tag":264,"props":528,"children":530},{"className":266,"code":529,"language":33,"meta":7,"style":7},"curl: (35) error:1409442E:SSL routines:ssl3_read_bytes:tlsv1 alert protocol version\n",[531],{"type":28,"tag":126,"props":532,"children":533},{"__ignoreMap":7},[534],{"type":28,"tag":273,"props":535,"children":536},{"class":275,"line":276},[537],{"type":28,"tag":273,"props":538,"children":539},{},[540],{"type":33,"value":529},{"type":28,"tag":29,"props":542,"children":543},{},[544,548],{"type":28,"tag":36,"props":545,"children":546},{},[547],{"type":33,"value":344},{"type":33,"value":549}," you offered a TLS version the other side has disabled. Typically an older client (TLS 1.0/1.1 only) hitting a server that now requires TLS 1.2+.",{"type":28,"tag":29,"props":551,"children":552},{},[553,557],{"type":28,"tag":36,"props":554,"children":555},{},[556],{"type":33,"value":354},{"type":33,"value":558}," upgrade the client's TLS library, or route the request through something that can negotiate the version the server expects.",{"type":28,"tag":85,"props":560,"children":562},{"id":561},"error1408f10bssl-routinesssl3_get_recordwrong-version-number",[563],{"type":28,"tag":126,"props":564,"children":566},{"className":565},[],[567],{"type":33,"value":568},"error:1408F10B:SSL routines:ssl3_get_record:wrong version number",{"type":28,"tag":29,"props":570,"children":571},{},[572,574,579],{"type":33,"value":573},"This one is a common red herring — it's usually ",{"type":28,"tag":36,"props":575,"children":576},{},[577],{"type":33,"value":578},"not",{"type":33,"value":580}," a TLS version mismatch.",{"type":28,"tag":264,"props":582,"children":584},{"className":266,"code":583,"language":33,"meta":7,"style":7},"curl: (35) error:1408F10B:SSL routines:ssl3_get_record:wrong version number\n\n# OpenSSL 3.x\nerror:0A00010B:SSL routines::wrong version number\n",[585],{"type":28,"tag":126,"props":586,"children":587},{"__ignoreMap":7},[588,596,603,610],{"type":28,"tag":273,"props":589,"children":590},{"class":275,"line":276},[591],{"type":28,"tag":273,"props":592,"children":593},{},[594],{"type":33,"value":595},"curl: (35) error:1408F10B:SSL routines:ssl3_get_record:wrong version number\n",{"type":28,"tag":273,"props":597,"children":598},{"class":275,"line":285},[599],{"type":28,"tag":273,"props":600,"children":601},{"emptyLinePlaceholder":289},[602],{"type":33,"value":292},{"type":28,"tag":273,"props":604,"children":605},{"class":275,"line":295},[606],{"type":28,"tag":273,"props":607,"children":608},{},[609],{"type":33,"value":477},{"type":28,"tag":273,"props":611,"children":612},{"class":275,"line":304},[613],{"type":28,"tag":273,"props":614,"children":615},{},[616],{"type":33,"value":617},"error:0A00010B:SSL routines::wrong version number\n",{"type":28,"tag":29,"props":619,"children":620},{},[621,625],{"type":28,"tag":36,"props":622,"children":623},{},[624],{"type":33,"value":344},{"type":33,"value":626}," the bytes received don't look like a TLS record at all. Almost always one of:",{"type":28,"tag":628,"props":629,"children":630},"ul",{},[631,650,655],{"type":28,"tag":632,"props":633,"children":634},"li",{},[635,637,648],{"type":33,"value":636},"You sent ",{"type":28,"tag":36,"props":638,"children":639},{},[640,646],{"type":28,"tag":126,"props":641,"children":643},{"className":642},[],[644],{"type":33,"value":645},"https://",{"type":33,"value":647}," to a port that's serving plain HTTP",{"type":33,"value":649}," (or vice-versa).",{"type":28,"tag":632,"props":651,"children":652},{},[653],{"type":33,"value":654},"A proxy or load balancer terminated TLS and is forwarding cleartext.",{"type":28,"tag":632,"props":656,"children":657},{},[658],{"type":33,"value":659},"The wrong port entirely.",{"type":28,"tag":29,"props":661,"children":662},{},[663,668,670,675,677,683],{"type":28,"tag":36,"props":664,"children":665},{},[666],{"type":33,"value":667},"Fix:",{"type":33,"value":669}," check the scheme and port before anything else — match ",{"type":28,"tag":126,"props":671,"children":673},{"className":672},[],[674],{"type":33,"value":645},{"type":33,"value":676}," to the TLS port and ",{"type":28,"tag":126,"props":678,"children":680},{"className":679},[],[681],{"type":33,"value":682},"http://",{"type":33,"value":684}," to the plaintext one.",{"type":28,"tag":85,"props":686,"children":688},{"id":687},"received-fatal-alert-protocol_version-java",[689,695],{"type":28,"tag":126,"props":690,"children":692},{"className":691},[],[693],{"type":33,"value":694},"received fatal alert: protocol_version",{"type":33,"value":696}," (Java)",{"type":28,"tag":29,"props":698,"children":699},{},[700],{"type":33,"value":701},"The Java/JSSE wording for the same protocol-version rejection above.",{"type":28,"tag":264,"props":703,"children":705},{"className":266,"code":704,"language":33,"meta":7,"style":7},"javax.net.ssl.SSLHandshakeException: Received fatal alert: protocol_version\n\n# A related JSSE message when the JVM has disabled the only protocol on offer:\njavax.net.ssl.SSLHandshakeException: No appropriate protocol\n  (protocol is disabled or cipher suites are inappropriate)\n",[706],{"type":28,"tag":126,"props":707,"children":708},{"__ignoreMap":7},[709,717,724,732,740],{"type":28,"tag":273,"props":710,"children":711},{"class":275,"line":276},[712],{"type":28,"tag":273,"props":713,"children":714},{},[715],{"type":33,"value":716},"javax.net.ssl.SSLHandshakeException: Received fatal alert: protocol_version\n",{"type":28,"tag":273,"props":718,"children":719},{"class":275,"line":285},[720],{"type":28,"tag":273,"props":721,"children":722},{"emptyLinePlaceholder":289},[723],{"type":33,"value":292},{"type":28,"tag":273,"props":725,"children":726},{"class":275,"line":295},[727],{"type":28,"tag":273,"props":728,"children":729},{},[730],{"type":33,"value":731},"# A related JSSE message when the JVM has disabled the only protocol on offer:\n",{"type":28,"tag":273,"props":733,"children":734},{"class":275,"line":304},[735],{"type":28,"tag":273,"props":736,"children":737},{},[738],{"type":33,"value":739},"javax.net.ssl.SSLHandshakeException: No appropriate protocol\n",{"type":28,"tag":273,"props":741,"children":742},{"class":275,"line":313},[743],{"type":28,"tag":273,"props":744,"children":745},{},[746],{"type":33,"value":747},"  (protocol is disabled or cipher suites are inappropriate)\n",{"type":28,"tag":29,"props":749,"children":750},{},[751,755,757,763],{"type":28,"tag":36,"props":752,"children":753},{},[754],{"type":33,"value":344},{"type":33,"value":756}," the JVM and the peer have no enabled TLS version in common. Modern JDKs disable TLS 1.0/1.1 in ",{"type":28,"tag":126,"props":758,"children":760},{"className":759},[],[761],{"type":33,"value":762},"jdk.tls.disabledAlgorithms",{"type":33,"value":764},", so a JVM talking to a legacy endpoint (or an old JVM talking to a hardened one) fails here.",{"type":28,"tag":29,"props":766,"children":767},{},[768,772,774,780,782,788,790,795,797,802],{"type":28,"tag":36,"props":769,"children":770},{},[771],{"type":33,"value":354},{"type":33,"value":773}," align the protocol versions (",{"type":28,"tag":126,"props":775,"children":777},{"className":776},[],[778],{"type":33,"value":779},"-Dhttps.protocols=TLSv1.2",{"type":33,"value":781},"), or update ",{"type":28,"tag":126,"props":783,"children":785},{"className":784},[],[786],{"type":33,"value":787},"java.security",{"type":33,"value":789},". If a legacy Java service is ",{"type":28,"tag":49,"props":791,"children":792},{},[793],{"type":33,"value":794},"posting",{"type":33,"value":796}," webhooks and can't reach a modern endpoint, give it a ",{"type":28,"tag":76,"props":798,"children":799},{"href":78},[800],{"type":33,"value":801},"Webhook Relay input that accepts its TLS version",{"type":33,"value":803}," instead of relaxing JVM-wide security policy.",{"type":28,"tag":85,"props":805,"children":807},{"id":806},"ssl-no_protocols_available-no-protocols-available-python",[808,814],{"type":28,"tag":126,"props":809,"children":811},{"className":810},[],[812],{"type":33,"value":813},"[SSL: NO_PROTOCOLS_AVAILABLE] no protocols available",{"type":33,"value":815}," (Python)",{"type":28,"tag":264,"props":817,"children":819},{"className":266,"code":818,"language":33,"meta":7,"style":7},"ssl.SSLError: [SSL: NO_PROTOCOLS_AVAILABLE] no protocols available (_ssl.c:997)\n\n# Often surfaced through requests as:\nrequests.exceptions.SSLError: HTTPSConnectionPool(host='...', port=443):\n  Max retries exceeded ... [SSL: NO_PROTOCOLS_AVAILABLE] no protocols available\n",[820],{"type":28,"tag":126,"props":821,"children":822},{"__ignoreMap":7},[823,831,838,846,854],{"type":28,"tag":273,"props":824,"children":825},{"class":275,"line":276},[826],{"type":28,"tag":273,"props":827,"children":828},{},[829],{"type":33,"value":830},"ssl.SSLError: [SSL: NO_PROTOCOLS_AVAILABLE] no protocols available (_ssl.c:997)\n",{"type":28,"tag":273,"props":832,"children":833},{"class":275,"line":285},[834],{"type":28,"tag":273,"props":835,"children":836},{"emptyLinePlaceholder":289},[837],{"type":33,"value":292},{"type":28,"tag":273,"props":839,"children":840},{"class":275,"line":295},[841],{"type":28,"tag":273,"props":842,"children":843},{},[844],{"type":33,"value":845},"# Often surfaced through requests as:\n",{"type":28,"tag":273,"props":847,"children":848},{"class":275,"line":304},[849],{"type":28,"tag":273,"props":850,"children":851},{},[852],{"type":33,"value":853},"requests.exceptions.SSLError: HTTPSConnectionPool(host='...', port=443):\n",{"type":28,"tag":273,"props":855,"children":856},{"class":275,"line":313},[857],{"type":28,"tag":273,"props":858,"children":859},{},[860],{"type":33,"value":861},"  Max retries exceeded ... [SSL: NO_PROTOCOLS_AVAILABLE] no protocols available\n",{"type":28,"tag":29,"props":863,"children":864},{},[865,869,871,877],{"type":28,"tag":36,"props":866,"children":867},{},[868],{"type":33,"value":344},{"type":33,"value":870}," every protocol version Python's ",{"type":28,"tag":126,"props":872,"children":874},{"className":873},[],[875],{"type":33,"value":876},"ssl",{"type":33,"value":878}," module would offer has been disabled (commonly because the OpenSSL build disabled TLS 1.0/1.1 and the target supports nothing newer).",{"type":28,"tag":29,"props":880,"children":881},{},[882,886,888,894],{"type":28,"tag":36,"props":883,"children":884},{},[885],{"type":33,"value":354},{"type":33,"value":887}," target an endpoint that supports TLS 1.2+, or — only when you control and trust the legacy endpoint — lower ",{"type":28,"tag":126,"props":889,"children":891},{"className":890},[],[892],{"type":33,"value":893},"ssl.SSLContext.minimum_version",{"type":33,"value":895},".",{"type":28,"tag":85,"props":897,"children":899},{"id":898},"err_ssl_version_or_cipher_mismatch-chrome-edge",[900,905],{"type":28,"tag":126,"props":901,"children":903},{"className":902},[],[904],{"type":33,"value":146},{"type":33,"value":906}," (Chrome / Edge)",{"type":28,"tag":29,"props":908,"children":909},{},[910],{"type":33,"value":911},"The browser equivalent, and by far the most-searched of this family.",{"type":28,"tag":264,"props":913,"children":915},{"className":266,"code":914,"language":33,"meta":7,"style":7},"This site can't provide a secure connection\nexample.com uses an unsupported protocol.\nERR_SSL_VERSION_OR_CIPHER_MISMATCH\n\n# In the console / network log:\nnet::ERR_SSL_VERSION_OR_CIPHER_MISMATCH\n\n# Firefox phrases it as:\nSecure Connection Failed — SSL_ERROR_UNSUPPORTED_VERSION\nSSL_ERROR_NO_CYPHER_OVERLAP\n",[916],{"type":28,"tag":126,"props":917,"children":918},{"__ignoreMap":7},[919,927,935,943,950,958,966,973,981,990],{"type":28,"tag":273,"props":920,"children":921},{"class":275,"line":276},[922],{"type":28,"tag":273,"props":923,"children":924},{},[925],{"type":33,"value":926},"This site can't provide a secure connection\n",{"type":28,"tag":273,"props":928,"children":929},{"class":275,"line":285},[930],{"type":28,"tag":273,"props":931,"children":932},{},[933],{"type":33,"value":934},"example.com uses an unsupported protocol.\n",{"type":28,"tag":273,"props":936,"children":937},{"class":275,"line":295},[938],{"type":28,"tag":273,"props":939,"children":940},{},[941],{"type":33,"value":942},"ERR_SSL_VERSION_OR_CIPHER_MISMATCH\n",{"type":28,"tag":273,"props":944,"children":945},{"class":275,"line":304},[946],{"type":28,"tag":273,"props":947,"children":948},{"emptyLinePlaceholder":289},[949],{"type":33,"value":292},{"type":28,"tag":273,"props":951,"children":952},{"class":275,"line":313},[953],{"type":28,"tag":273,"props":954,"children":955},{},[956],{"type":33,"value":957},"# In the console / network log:\n",{"type":28,"tag":273,"props":959,"children":960},{"class":275,"line":321},[961],{"type":28,"tag":273,"props":962,"children":963},{},[964],{"type":33,"value":965},"net::ERR_SSL_VERSION_OR_CIPHER_MISMATCH\n",{"type":28,"tag":273,"props":967,"children":968},{"class":275,"line":330},[969],{"type":28,"tag":273,"props":970,"children":971},{"emptyLinePlaceholder":289},[972],{"type":33,"value":292},{"type":28,"tag":273,"props":974,"children":975},{"class":275,"line":480},[976],{"type":28,"tag":273,"props":977,"children":978},{},[979],{"type":33,"value":980},"# Firefox phrases it as:\n",{"type":28,"tag":273,"props":982,"children":984},{"class":275,"line":983},9,[985],{"type":28,"tag":273,"props":986,"children":987},{},[988],{"type":33,"value":989},"Secure Connection Failed — SSL_ERROR_UNSUPPORTED_VERSION\n",{"type":28,"tag":273,"props":991,"children":993},{"class":275,"line":992},10,[994],{"type":28,"tag":273,"props":995,"children":996},{},[997],{"type":33,"value":998},"SSL_ERROR_NO_CYPHER_OVERLAP\n",{"type":28,"tag":29,"props":1000,"children":1001},{},[1002,1006],{"type":28,"tag":36,"props":1003,"children":1004},{},[1005],{"type":33,"value":344},{"type":33,"value":1007}," the browser (which has dropped TLS 1.0/1.1 and weak ciphers) and the server share no protocol version or cipher. The server is usually too old or misconfigured.",{"type":28,"tag":29,"props":1009,"children":1010},{},[1011,1015],{"type":28,"tag":36,"props":1012,"children":1013},{},[1014],{"type":33,"value":354},{"type":33,"value":1016}," enable TLS 1.2/1.3 and a modern cipher suite on the server, and make sure the certificate isn't using a deprecated signature.",{"type":28,"tag":85,"props":1018,"children":1020},{"id":1019},"error-525-ssl-handshake-failed-cloudflare",[1021,1027],{"type":28,"tag":126,"props":1022,"children":1024},{"className":1023},[],[1025],{"type":33,"value":1026},"Error 525: SSL handshake failed",{"type":33,"value":1028}," (Cloudflare)",{"type":28,"tag":264,"props":1030,"children":1032},{"className":266,"code":1031,"language":33,"meta":7,"style":7},"Error 525: SSL handshake failed\n",[1033],{"type":28,"tag":126,"props":1034,"children":1035},{"__ignoreMap":7},[1036],{"type":28,"tag":273,"props":1037,"children":1038},{"class":275,"line":276},[1039],{"type":28,"tag":273,"props":1040,"children":1041},{},[1042],{"type":33,"value":1031},{"type":28,"tag":29,"props":1044,"children":1045},{},[1046,1050],{"type":28,"tag":36,"props":1047,"children":1048},{},[1049],{"type":33,"value":344},{"type":33,"value":1051}," Cloudflare (a modern TLS client) couldn't complete the handshake with your origin server — typically the origin requires an older protocol, presents an incomplete certificate chain, or isn't listening on 443.",{"type":28,"tag":29,"props":1053,"children":1054},{},[1055,1059],{"type":28,"tag":36,"props":1056,"children":1057},{},[1058],{"type":33,"value":354},{"type":33,"value":1060}," ensure the origin supports the TLS version Cloudflare offers and serves a complete, valid certificate chain.",{"type":28,"tag":85,"props":1062,"children":1064},{"id":1063},"remote-error-tls-protocol-version-not-supported-go",[1065,1071],{"type":28,"tag":126,"props":1066,"children":1068},{"className":1067},[],[1069],{"type":33,"value":1070},"remote error: tls: protocol version not supported",{"type":33,"value":1072}," (Go)",{"type":28,"tag":264,"props":1074,"children":1076},{"className":266,"code":1075,"language":33,"meta":7,"style":7},"remote error: tls: protocol version not supported\ntls: server selected unsupported protocol version 301\n",[1077],{"type":28,"tag":126,"props":1078,"children":1079},{"__ignoreMap":7},[1080,1088],{"type":28,"tag":273,"props":1081,"children":1082},{"class":275,"line":276},[1083],{"type":28,"tag":273,"props":1084,"children":1085},{},[1086],{"type":33,"value":1087},"remote error: tls: protocol version not supported\n",{"type":28,"tag":273,"props":1089,"children":1090},{"class":275,"line":285},[1091],{"type":28,"tag":273,"props":1092,"children":1093},{},[1094],{"type":33,"value":1095},"tls: server selected unsupported protocol version 301\n",{"type":28,"tag":29,"props":1097,"children":1098},{},[1099,1103,1105,1111,1113,1119,1121,1127],{"type":28,"tag":36,"props":1100,"children":1101},{},[1102],{"type":33,"value":344},{"type":33,"value":1104}," Go's ",{"type":28,"tag":126,"props":1106,"children":1108},{"className":1107},[],[1109],{"type":33,"value":1110},"crypto/tls",{"type":33,"value":1112}," sets ",{"type":28,"tag":126,"props":1114,"children":1116},{"className":1115},[],[1117],{"type":33,"value":1118},"MinVersion",{"type":33,"value":1120}," to TLS 1.2 by default, so it refuses an endpoint that offers only TLS 1.0 (version ",{"type":28,"tag":126,"props":1122,"children":1124},{"className":1123},[],[1125],{"type":33,"value":1126},"301",{"type":33,"value":1128},") or 1.1.",{"type":28,"tag":29,"props":1130,"children":1131},{},[1132,1136,1138,1144],{"type":28,"tag":36,"props":1133,"children":1134},{},[1135],{"type":33,"value":354},{"type":33,"value":1137}," only if you control the endpoint, set a lower ",{"type":28,"tag":126,"props":1139,"children":1141},{"className":1140},[],[1142],{"type":33,"value":1143},"tls.Config{MinVersion: tls.VersionTLS10}",{"type":33,"value":1145}," — but prefer upgrading the endpoint or bridging it.",{"type":28,"tag":85,"props":1147,"children":1149},{"id":1148},"certificate-verify-failed-self-signed-certificate-unable-to-verify-the-first-certificate",[1150,1155,1156,1161,1162],{"type":28,"tag":126,"props":1151,"children":1153},{"className":1152},[],[1154],{"type":33,"value":228},{"type":33,"value":133},{"type":28,"tag":126,"props":1157,"children":1159},{"className":1158},[],[1160],{"type":33,"value":235},{"type":33,"value":133},{"type":28,"tag":126,"props":1163,"children":1165},{"className":1164},[],[1166],{"type":33,"value":242},{"type":28,"tag":29,"props":1168,"children":1169},{},[1170,1172,1177],{"type":33,"value":1171},"A different failure mode: the protocol version is fine, but the client can't ",{"type":28,"tag":36,"props":1173,"children":1174},{},[1175],{"type":33,"value":1176},"verify the endpoint's certificate",{"type":33,"value":1178}," against a trusted CA.",{"type":28,"tag":264,"props":1180,"children":1182},{"className":266,"code":1181,"language":33,"meta":7,"style":7},"# curl\ncurl: (60) SSL certificate problem: self-signed certificate\ncurl: (60) SSL certificate problem: unable to get local issuer certificate\n\n# Node.js\nError: unable to verify the first certificate (UNABLE_TO_VERIFY_LEAF_SIGNATURE)\nError: self-signed certificate in certificate chain\n\n# Python\nssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED]\n  certificate verify failed: self signed certificate (_ssl.c:1007)\n\n# Go\nx509: certificate signed by unknown authority\n\n# Chrome\nNET::ERR_CERT_AUTHORITY_INVALID\n",[1183],{"type":28,"tag":126,"props":1184,"children":1185},{"__ignoreMap":7},[1186,1194,1202,1210,1217,1225,1233,1241,1248,1255,1263,1271,1279,1288,1297,1305,1314],{"type":28,"tag":273,"props":1187,"children":1188},{"class":275,"line":276},[1189],{"type":28,"tag":273,"props":1190,"children":1191},{},[1192],{"type":33,"value":1193},"# curl\n",{"type":28,"tag":273,"props":1195,"children":1196},{"class":275,"line":285},[1197],{"type":28,"tag":273,"props":1198,"children":1199},{},[1200],{"type":33,"value":1201},"curl: (60) SSL certificate problem: self-signed certificate\n",{"type":28,"tag":273,"props":1203,"children":1204},{"class":275,"line":295},[1205],{"type":28,"tag":273,"props":1206,"children":1207},{},[1208],{"type":33,"value":1209},"curl: (60) SSL certificate problem: unable to get local issuer certificate\n",{"type":28,"tag":273,"props":1211,"children":1212},{"class":275,"line":304},[1213],{"type":28,"tag":273,"props":1214,"children":1215},{"emptyLinePlaceholder":289},[1216],{"type":33,"value":292},{"type":28,"tag":273,"props":1218,"children":1219},{"class":275,"line":313},[1220],{"type":28,"tag":273,"props":1221,"children":1222},{},[1223],{"type":33,"value":1224},"# Node.js\n",{"type":28,"tag":273,"props":1226,"children":1227},{"class":275,"line":321},[1228],{"type":28,"tag":273,"props":1229,"children":1230},{},[1231],{"type":33,"value":1232},"Error: unable to verify the first certificate (UNABLE_TO_VERIFY_LEAF_SIGNATURE)\n",{"type":28,"tag":273,"props":1234,"children":1235},{"class":275,"line":330},[1236],{"type":28,"tag":273,"props":1237,"children":1238},{},[1239],{"type":33,"value":1240},"Error: self-signed certificate in certificate chain\n",{"type":28,"tag":273,"props":1242,"children":1243},{"class":275,"line":480},[1244],{"type":28,"tag":273,"props":1245,"children":1246},{"emptyLinePlaceholder":289},[1247],{"type":33,"value":292},{"type":28,"tag":273,"props":1249,"children":1250},{"class":275,"line":983},[1251],{"type":28,"tag":273,"props":1252,"children":1253},{},[1254],{"type":33,"value":454},{"type":28,"tag":273,"props":1256,"children":1257},{"class":275,"line":992},[1258],{"type":28,"tag":273,"props":1259,"children":1260},{},[1261],{"type":33,"value":1262},"ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED]\n",{"type":28,"tag":273,"props":1264,"children":1265},{"class":275,"line":16},[1266],{"type":28,"tag":273,"props":1267,"children":1268},{},[1269],{"type":33,"value":1270},"  certificate verify failed: self signed certificate (_ssl.c:1007)\n",{"type":28,"tag":273,"props":1272,"children":1274},{"class":275,"line":1273},12,[1275],{"type":28,"tag":273,"props":1276,"children":1277},{"emptyLinePlaceholder":289},[1278],{"type":33,"value":292},{"type":28,"tag":273,"props":1280,"children":1282},{"class":275,"line":1281},13,[1283],{"type":28,"tag":273,"props":1284,"children":1285},{},[1286],{"type":33,"value":1287},"# Go\n",{"type":28,"tag":273,"props":1289,"children":1291},{"class":275,"line":1290},14,[1292],{"type":28,"tag":273,"props":1293,"children":1294},{},[1295],{"type":33,"value":1296},"x509: certificate signed by unknown authority\n",{"type":28,"tag":273,"props":1298,"children":1300},{"class":275,"line":1299},15,[1301],{"type":28,"tag":273,"props":1302,"children":1303},{"emptyLinePlaceholder":289},[1304],{"type":33,"value":292},{"type":28,"tag":273,"props":1306,"children":1308},{"class":275,"line":1307},16,[1309],{"type":28,"tag":273,"props":1310,"children":1311},{},[1312],{"type":33,"value":1313},"# Chrome\n",{"type":28,"tag":273,"props":1315,"children":1317},{"class":275,"line":1316},17,[1318],{"type":28,"tag":273,"props":1319,"children":1320},{},[1321],{"type":33,"value":1322},"NET::ERR_CERT_AUTHORITY_INVALID\n",{"type":28,"tag":29,"props":1324,"children":1325},{},[1326,1330],{"type":28,"tag":36,"props":1327,"children":1328},{},[1329],{"type":33,"value":344},{"type":33,"value":1331}," the endpoint presents a certificate that isn't signed by a publicly trusted CA — a self-signed cert, a private/internal CA, an incomplete chain, or an expired certificate.",{"type":28,"tag":29,"props":1333,"children":1334},{},[1335,1339,1341,1346],{"type":28,"tag":36,"props":1336,"children":1337},{},[1338],{"type":33,"value":354},{"type":33,"value":1340}," install a publicly trusted certificate, or send the full chain (including intermediates). When the destination is an internal or legacy box you control and trust, ",{"type":28,"tag":76,"props":1342,"children":1343},{"href":78},[1344],{"type":33,"value":1345},"Webhook Relay can skip verification for that one destination",{"type":33,"value":895},{"type":28,"tag":85,"props":1348,"children":1350},{"id":1349},"how-webhook-relay-bridges-the-gap",[1351],{"type":33,"value":1352},"How Webhook Relay bridges the gap",{"type":28,"tag":29,"props":1354,"children":1355},{},[1356,1358,1363,1365,1370],{"type":33,"value":1357},"Webhook Relay terminates TLS independently on the way ",{"type":28,"tag":36,"props":1359,"children":1360},{},[1361],{"type":33,"value":1362},"in",{"type":33,"value":1364}," (the input that receives webhooks) and on the way ",{"type":28,"tag":36,"props":1366,"children":1367},{},[1368],{"type":33,"value":1369},"out",{"type":33,"value":1371}," (delivery to your destination), so the two legs don't have to share the same TLS settings. The controls live in two places.",{"type":28,"tag":1373,"props":1374,"children":1376},"h3",{"id":1375},"accept-legacy-senders-tls-compatibility-on-the-input",[1377],{"type":33,"value":1378},"Accept legacy senders — TLS compatibility on the input",{"type":28,"tag":29,"props":1380,"children":1381},{},[1382,1384,1389,1391,1396],{"type":33,"value":1383},"The version and cipher errors above happen when a ",{"type":28,"tag":36,"props":1385,"children":1386},{},[1387],{"type":33,"value":1388},"legacy sender",{"type":33,"value":1390}," can't complete a modern handshake. If that sender is delivering webhooks to you, you don't have to weaken anything else — just relax TLS on the ",{"type":28,"tag":36,"props":1392,"children":1393},{},[1394],{"type":33,"value":1395},"input",{"type":33,"value":1397}," it posts to.",{"type":28,"tag":29,"props":1399,"children":1400},{},[1401,1403,1408],{"type":33,"value":1402},"Each input has a ",{"type":28,"tag":36,"props":1404,"children":1405},{},[1406],{"type":33,"value":1407},"TLS compatibility",{"type":33,"value":1409}," setting with two controls:",{"type":28,"tag":628,"props":1411,"children":1412},{},[1413,1444],{"type":28,"tag":632,"props":1414,"children":1415},{},[1416,1421,1423,1428,1430,1435,1437,1442],{"type":28,"tag":36,"props":1417,"children":1418},{},[1419],{"type":33,"value":1420},"TLS version",{"type":33,"value":1422}," — the ",{"type":28,"tag":49,"props":1424,"children":1425},{},[1426],{"type":33,"value":1427},"minimum",{"type":33,"value":1429}," version the input accepts. The default is ",{"type":28,"tag":36,"props":1431,"children":1432},{},[1433],{"type":33,"value":1434},"TLS 1.3",{"type":33,"value":1436},"; lower it to ",{"type":28,"tag":36,"props":1438,"children":1439},{},[1440],{"type":33,"value":1441},"TLS 1.2",{"type":33,"value":1443}," for senders that still require it (PayPal webhooks, for example), or further when you must.",{"type":28,"tag":632,"props":1445,"children":1446},{},[1447,1452,1454,1459,1461,1466,1468,1473,1475,1480],{"type":28,"tag":36,"props":1448,"children":1449},{},[1450],{"type":33,"value":1451},"Legacy TLS compatibility (TLS 1.0 + wide ciphers)",{"type":33,"value":1453}," — a toggle that makes the input accept TLS versions ",{"type":28,"tag":36,"props":1455,"children":1456},{},[1457],{"type":33,"value":1458},"down to 1.0 and a wider legacy cipher set",{"type":33,"value":1460},", for the oldest systems that would otherwise fail with ",{"type":28,"tag":126,"props":1462,"children":1464},{"className":1463},[],[1465],{"type":33,"value":163},{"type":33,"value":1467},", ",{"type":28,"tag":126,"props":1469,"children":1471},{"className":1470},[],[1472],{"type":33,"value":131},{"type":33,"value":1474}," or ",{"type":28,"tag":126,"props":1476,"children":1478},{"className":1477},[],[1479],{"type":33,"value":146},{"type":33,"value":895},{"type":28,"tag":29,"props":1482,"children":1483},{},[1484],{"type":28,"tag":1485,"props":1486,"children":1489},"img",{"alt":1487,"src":1488},"Per-input TLS compatibility settings — a minimum TLS version dropdown and a \"Legacy TLS compatibility (TLS 1.0 + wide ciphers)\" toggle","/images/docs/webhooks/tls/tls_settings.png",[],{"type":28,"tag":29,"props":1491,"children":1492},{},[1493],{"type":33,"value":1494},"Webhook Relay accepts the old handshake on that input and forwards the event onward over modern TLS — so one legacy sender no longer forces you to lower TLS across your whole stack.",{"type":28,"tag":1496,"props":1497,"children":1498},"hint",{},[1499],{"type":28,"tag":29,"props":1500,"children":1501},{},[1502,1504,1509,1511,1515,1517,1522,1524,1529,1531,1536,1538,1544,1545,1551],{"type":33,"value":1503},"Legacy settings apply ",{"type":28,"tag":36,"props":1505,"children":1506},{},[1507],{"type":33,"value":1508},"per input domain",{"type":33,"value":1510}," and lower the security baseline, so enable them only on the inputs that genuinely need them. Setting a custom minimum ",{"type":28,"tag":36,"props":1512,"children":1513},{},[1514],{"type":33,"value":1420},{"type":33,"value":1516}," is available on ",{"type":28,"tag":36,"props":1518,"children":1519},{},[1520],{"type":33,"value":1521},"Business and Pro",{"type":33,"value":1523},"; the ",{"type":28,"tag":36,"props":1525,"children":1526},{},[1527],{"type":33,"value":1528},"Legacy TLS compatibility",{"type":33,"value":1530}," toggle (down to TLS 1.0 + wide ciphers) is available on ",{"type":28,"tag":36,"props":1532,"children":1533},{},[1534],{"type":33,"value":1535},"Pro",{"type":33,"value":1537},". See the ",{"type":28,"tag":76,"props":1539,"children":1541},{"href":1540},"/features/tls-compatibility",[1542],{"type":33,"value":1543},"TLS compatibility feature",{"type":33,"value":55},{"type":28,"tag":76,"props":1546,"children":1548},{"href":1547},"/pricing",[1549],{"type":33,"value":1550},"pricing",{"type":33,"value":895},{"type":28,"tag":1373,"props":1553,"children":1555},{"id":1554},"deliver-to-non-standard-certificates-tls-verification-on-the-output",[1556],{"type":33,"value":1557},"Deliver to non-standard certificates — TLS verification on the output",{"type":28,"tag":29,"props":1559,"children":1560},{},[1561,1563,1568,1570,1575,1577,1582,1584,1589,1590,1595],{"type":33,"value":1562},"On the delivery side the relevant control is ",{"type":28,"tag":36,"props":1564,"children":1565},{},[1566],{"type":33,"value":1567},"TLS verification",{"type":33,"value":1569},", found per destination under ",{"type":28,"tag":36,"props":1571,"children":1572},{},[1573],{"type":33,"value":1574},"Delivery controls",{"type":33,"value":1576},". Leave it on for normal endpoints; switch it ",{"type":28,"tag":36,"props":1578,"children":1579},{},[1580],{"type":33,"value":1581},"off",{"type":33,"value":1583}," to deliver to a destination whose certificate can't be verified against public CAs — a self-signed cert, an internal CA or a legacy box — instead of failing with ",{"type":28,"tag":126,"props":1585,"children":1587},{"className":1586},[],[1588],{"type":33,"value":228},{"type":33,"value":1474},{"type":28,"tag":126,"props":1591,"children":1593},{"className":1592},[],[1594],{"type":33,"value":242},{"type":33,"value":895},{"type":28,"tag":29,"props":1597,"children":1598},{},[1599],{"type":28,"tag":1485,"props":1600,"children":1603},{"alt":1601,"src":1602},"Per-output Delivery controls with a TLS verification toggle","/images/docs/webhooks/tls/tls_output_disable_verification.png",[],{"type":28,"tag":29,"props":1605,"children":1606},{},[1607],{"type":33,"value":1608},"Only disable verification for destinations you control and trust, typically on a private or internal network.",{"type":28,"tag":85,"props":1610,"children":1612},{"id":1611},"turn-it-on",[1613],{"type":33,"value":1614},"Turn it on",{"type":28,"tag":29,"props":1616,"children":1617},{},[1618],{"type":28,"tag":36,"props":1619,"children":1620},{},[1621],{"type":33,"value":1622},"To accept a legacy sender (input):",{"type":28,"tag":1624,"props":1625,"children":1626},"ol",{},[1627,1643,1659],{"type":28,"tag":632,"props":1628,"children":1629},{},[1630,1632,1636,1638,1642],{"type":33,"value":1631},"Open the ",{"type":28,"tag":36,"props":1633,"children":1634},{},[1635],{"type":33,"value":1395},{"type":33,"value":1637}," the sender delivers to and find ",{"type":28,"tag":36,"props":1639,"children":1640},{},[1641],{"type":33,"value":1407},{"type":33,"value":895},{"type":28,"tag":632,"props":1644,"children":1645},{},[1646,1648,1652,1654,1658],{"type":33,"value":1647},"Set the ",{"type":28,"tag":36,"props":1649,"children":1650},{},[1651],{"type":33,"value":1420},{"type":33,"value":1653}," to the lowest version that sender needs, and/or turn on ",{"type":28,"tag":36,"props":1655,"children":1656},{},[1657],{"type":33,"value":1451},{"type":33,"value":895},{"type":28,"tag":632,"props":1660,"children":1661},{},[1662,1667],{"type":28,"tag":36,"props":1663,"children":1664},{},[1665],{"type":33,"value":1666},"Save",{"type":33,"value":1668},", then have the sender retry — the handshake now succeeds and the webhook is relayed onward.",{"type":28,"tag":29,"props":1670,"children":1671},{},[1672],{"type":28,"tag":36,"props":1673,"children":1674},{},[1675],{"type":33,"value":1676},"To deliver to a self-signed or internal certificate (output):",{"type":28,"tag":1624,"props":1678,"children":1679},{},[1680,1696,1707],{"type":28,"tag":632,"props":1681,"children":1682},{},[1683,1684,1689,1691,1695],{"type":33,"value":1631},{"type":28,"tag":36,"props":1685,"children":1686},{},[1687],{"type":33,"value":1688},"output destination",{"type":33,"value":1690}," and find ",{"type":28,"tag":36,"props":1692,"children":1693},{},[1694],{"type":33,"value":1574},{"type":33,"value":895},{"type":28,"tag":632,"props":1697,"children":1698},{},[1699,1701,1705],{"type":33,"value":1700},"Turn ",{"type":28,"tag":36,"props":1702,"children":1703},{},[1704],{"type":33,"value":1567},{"type":33,"value":1706}," off.",{"type":28,"tag":632,"props":1708,"children":1709},{},[1710],{"type":33,"value":1711},"Re-send a webhook and confirm it's delivered in the request log.",{"type":28,"tag":85,"props":1713,"children":1715},{"id":1714},"frequently-asked-questions",[1716],{"type":33,"value":1717},"Frequently asked questions",{"type":28,"tag":1373,"props":1719,"children":1721},{"id":1720},"why-do-i-get-unsupported-protocol-even-though-both-sides-support-tls",[1722],{"type":33,"value":1723},"Why do I get \"unsupported protocol\" even though both sides support TLS?",{"type":28,"tag":29,"props":1725,"children":1726},{},[1727,1729,1734,1736,1741,1743,1748],{"type":33,"value":1728},"They support TLS, but not the ",{"type":28,"tag":49,"props":1730,"children":1731},{},[1732],{"type":33,"value":1733},"same version",{"type":33,"value":1735},". Modern clients disable TLS 1.0/1.1; if the server only offers those, there is no version in common and the handshake fails with ",{"type":28,"tag":126,"props":1737,"children":1739},{"className":1738},[],[1740],{"type":33,"value":131},{"type":33,"value":1742}," or a ",{"type":28,"tag":126,"props":1744,"children":1746},{"className":1745},[],[1747],{"type":33,"value":139},{"type":33,"value":1749}," alert. One side has to meet the other — which is what a Webhook Relay input does when you lower its minimum TLS version or enable legacy TLS compatibility for a legacy sender.",{"type":28,"tag":1373,"props":1751,"children":1753},{"id":1752},"is-wrong-version-number-a-tls-version-problem",[1754],{"type":33,"value":1755},"Is \"wrong version number\" a TLS version problem?",{"type":28,"tag":29,"props":1757,"children":1758},{},[1759,1761,1766,1768,1773],{"type":33,"value":1760},"Usually not. ",{"type":28,"tag":126,"props":1762,"children":1764},{"className":1763},[],[1765],{"type":33,"value":187},{"type":33,"value":1767}," almost always means a scheme/port mismatch — ",{"type":28,"tag":126,"props":1769,"children":1771},{"className":1770},[],[1772],{"type":33,"value":645},{"type":33,"value":1774}," pointed at a plaintext HTTP port (or a proxy terminating TLS early). Check the URL scheme and port first.",{"type":28,"tag":1373,"props":1776,"children":1778},{"id":1777},"is-enabling-legacy-tls-1011-safe",[1779],{"type":33,"value":1780},"Is enabling legacy TLS 1.0/1.1 safe?",{"type":28,"tag":29,"props":1782,"children":1783},{},[1784,1786,1790,1792,1797],{"type":33,"value":1785},"TLS 1.0 and 1.1 are deprecated and shouldn't be used on the public internet. Webhook Relay applies legacy TLS settings ",{"type":28,"tag":36,"props":1787,"children":1788},{},[1789],{"type":33,"value":1508},{"type":33,"value":1791},", so the safe pattern is to enable them ",{"type":28,"tag":36,"props":1793,"children":1794},{},[1795],{"type":33,"value":1796},"only on the one input a legacy sender needs",{"type":33,"value":1798}," and leave every other input on the modern TLS 1.3 default.",{"type":28,"tag":1373,"props":1800,"children":1802},{"id":1801},"can-i-force-a-minimum-tls-version-for-compliance",[1803],{"type":33,"value":1804},"Can I force a minimum TLS version for compliance?",{"type":28,"tag":29,"props":1806,"children":1807},{},[1808,1810,1814,1816,1820],{"type":33,"value":1809},"Yes. Set a custom minimum ",{"type":28,"tag":36,"props":1811,"children":1812},{},[1813],{"type":33,"value":1420},{"type":33,"value":1815}," on an input (Business or Pro) and Webhook Relay refuses handshakes below it. To deliver to an endpoint whose certificate can't be verified, use the per-output ",{"type":28,"tag":36,"props":1817,"children":1818},{},[1819],{"type":33,"value":1567},{"type":33,"value":1821}," toggle instead.",{"type":28,"tag":85,"props":1823,"children":1825},{"id":1824},"related",[1826],{"type":33,"value":1827},"Related",{"type":28,"tag":628,"props":1829,"children":1830},{},[1831,1839,1848,1857],{"type":28,"tag":632,"props":1832,"children":1833},{},[1834],{"type":28,"tag":76,"props":1835,"children":1836},{"href":1540},[1837],{"type":33,"value":1838},"TLS compatibility — feature overview",{"type":28,"tag":632,"props":1840,"children":1841},{},[1842],{"type":28,"tag":76,"props":1843,"children":1845},{"href":1844},"/docs/webhooks/durable-webhooks",[1846],{"type":33,"value":1847},"Durable webhooks — reliable delivery with automatic retries",{"type":28,"tag":632,"props":1849,"children":1850},{},[1851],{"type":28,"tag":76,"props":1852,"children":1854},{"href":1853},"/docs/webhooks/custom-domains",[1855],{"type":33,"value":1856},"Custom webhook domains",{"type":28,"tag":632,"props":1858,"children":1859},{},[1860],{"type":28,"tag":76,"props":1861,"children":1862},{"href":1547},[1863],{"type":33,"value":1864},"Pricing",{"type":28,"tag":1866,"props":1867,"children":1868},"style",{},[1869],{"type":33,"value":1870},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}",{"title":7,"searchDepth":295,"depth":295,"links":1872},[1873,1874,1875,1876,1877,1878,1880,1882,1884,1886,1888,1890,1894,1895,1901],{"id":87,"depth":285,"text":90},{"id":250,"depth":285,"text":257},{"id":389,"depth":285,"text":396},{"id":507,"depth":285,"text":514},{"id":561,"depth":285,"text":568},{"id":687,"depth":285,"text":1879},"received fatal alert: protocol_version (Java)",{"id":806,"depth":285,"text":1881},"[SSL: NO_PROTOCOLS_AVAILABLE] no protocols available (Python)",{"id":898,"depth":285,"text":1883},"ERR_SSL_VERSION_OR_CIPHER_MISMATCH (Chrome / Edge)",{"id":1019,"depth":285,"text":1885},"Error 525: SSL handshake failed (Cloudflare)",{"id":1063,"depth":285,"text":1887},"remote error: tls: protocol version not supported (Go)",{"id":1148,"depth":285,"text":1889},"certificate verify failed / self-signed certificate / unable to verify the first certificate",{"id":1349,"depth":285,"text":1352,"children":1891},[1892,1893],{"id":1375,"depth":295,"text":1378},{"id":1554,"depth":295,"text":1557},{"id":1611,"depth":285,"text":1614},{"id":1714,"depth":285,"text":1717,"children":1896},[1897,1898,1899,1900],{"id":1720,"depth":295,"text":1723},{"id":1752,"depth":295,"text":1755},{"id":1777,"depth":295,"text":1780},{"id":1801,"depth":295,"text":1804},{"id":1824,"depth":285,"text":1827},"markdown","content:docs:webhooks:tls-ssl-errors.md","content","docs/webhooks/tls-ssl-errors.md","docs/webhooks/tls-ssl-errors","md",{"loc":4},[1910,1913,1916,1919,1922,1925,1928,1931],{"_path":1911,"title":1912},"/docs/installation/cli","CLI",{"_path":1914,"title":1915},"/docs/installation/docker","Docker container",{"_path":1917,"title":1918},"/docs/installation/docker-compose","Docker Compose",{"_path":1920,"title":1921},"/docs/installation/kubernetes","Kubernetes",{"_path":1923,"title":1924},"/docs/installation/autostart-windows","Autostart (Windows)",{"_path":1926,"title":1927},"/docs/installation/autostart-linux","Autostart (Linux)",{"_path":1929,"title":1930},"/docs/installation/autostart-macos","Autostart (MacOS)",{"_path":1932,"title":1933},"/docs/installation/behind-proxy","HTTP proxy configuration",[1935],{"_path":1936,"title":1937},"/docs/webhooks/internal/localhost","Receiving webhooks on localhost",[1939,1942,1945,1948],{"_path":1940,"title":1941},"/docs/webhooks/auth/username-password","Username and password",{"_path":1943,"title":1944},"/docs/webhooks/auth/hmac","HMAC",{"_path":1946,"title":1947},"/docs/webhooks/auth/jwt","JWT authentication",{"_path":1949,"title":1950},"/docs/webhooks/auth/http-method","Auth using request method",[1952,1955],{"_path":1953,"title":1954},"/docs/webhooks/public/public-destination","Forward to public URL",{"_path":1956,"title":1957},"/docs/webhooks/public/multiple-destination-urls","Multiple destinations",[1959],{"_path":1960,"title":1961},"/docs/webhooks/cron/using-cron-webhooks","Schedule recurring webhooks",[1963,1966,1969,1972,1975,1978,1981],{"_path":1964,"title":1965},"/docs/service-connections","Service Connections",{"_path":1967,"title":1968},"/docs/service-connections/aws_s3","AWS S3",{"_path":1970,"title":1971},"/docs/service-connections/aws_sns","AWS SNS",{"_path":1973,"title":1974},"/docs/service-connections/aws_sqs","AWS SQS",{"_path":1976,"title":1977},"/docs/service-connections/azure","Azure",{"_path":1979,"title":1980},"/docs/service-connections/gcp_gcs","GCP Cloud Storage",{"_path":1982,"title":1983},"/docs/service-connections/gcp_pubsub","GCP Pub/Sub",[1985,1988,1991,1994],{"_path":1986,"title":1987},"/docs/email","Receive emails as webhooks",{"_path":1989,"title":1990},"/docs/email/payload","Email webhook payload",{"_path":1992,"title":1993},"/docs/email/filtering-and-policy","Sender filtering & policy",{"_path":1995,"title":1996},"/docs/email/cli","Create & poll email addresses from the CLI",[1998,2001],{"_path":1999,"title":2000},"/docs/tunnels/demoing-your-website","Demoing your website",{"_path":2002,"title":2003},"/docs/tunnels/regions","Regions",[2005,2008,2011,2014],{"_path":2006,"title":2007},"/docs/account/account-management","Account management",{"_path":2009,"title":2010},"/docs/account/mfa","Multi-factor authentication (MFA)",{"_path":2012,"title":2013},"/docs/account/team","Teams and sub-accounts",{"_path":2015,"title":2016},"/docs/account/billing-and-subscriptions","Billing & subscriptions",[2018,2021,2024],{"_path":2019,"title":2020},"/docs/tutorials/n8n/email-trigger","n8n Email Trigger (Inbound Email)",{"_path":2022,"title":2023},"/docs/tutorials/n8n/webhook-trigger","n8n Webhook Trigger (No Public IP)",{"_path":2025,"title":2026},"/docs/tutorials/n8n/whatsapp-cloud-api-webhook","n8n WhatsApp Cloud API Webhook Setup",[2028,2031,2034,2037,2040,2043,2046,2049],{"_path":2029,"title":2030},"/docs/tutorials/email/airtable","Email to Airtable",{"_path":2032,"title":2033},"/docs/tutorials/email/api","Email to API",{"_path":2035,"title":2036},"/docs/tutorials/email/database","Email to Database",{"_path":2038,"title":2039},"/docs/tutorials/email/discord","Email to Discord",{"_path":2041,"title":2042},"/docs/tutorials/email/google-sheets","Email to Google Sheets",{"_path":2044,"title":2045},"/docs/tutorials/email/microsoft-teams","Email to Microsoft Teams",{"_path":2047,"title":2048},"/docs/tutorials/email/notion","Email to Notion",{"_path":2050,"title":2051},"/docs/tutorials/email/slack","Email to Slack",[2053,2056,2059,2062,2065,2068,2071],{"_path":2054,"title":2055},"/docs/tutorials/cicd/jenkins-bitbucket","Jenkins and Bitbucket",{"_path":2057,"title":2058},"/docs/tutorials/cicd/jenkins-github","Jenkins and GitHub",{"_path":2060,"title":2061},"/docs/tutorials/cicd/jenkins-plugin","Jenkins Plugin",{"_path":2063,"title":2064},"/docs/tutorials/cicd/jenkins-plugin-multibranch","Jenkins Multibranch Pipelines",{"_path":2066,"title":2067},"/docs/tutorials/cicd/kubernetes-operator","Kubernetes Operator",{"_path":2069,"title":2070},"/docs/tutorials/cicd/terraform-atlantis","Terraform Atlantis",{"_path":2072,"title":2073},"/docs/tutorials/cicd/webhook-exec","Execute scripts on webhook",[2075,2078,2081],{"_path":2076,"title":2077},"/docs/tutorials/edge/home-assistant","Home Assistant",{"_path":2079,"title":2080},"/docs/tutorials/edge/javascript-app","JavaScript app",{"_path":2082,"title":2083},"/docs/tutorials/edge/node-red","Node-RED",[2085],{"_path":2086,"title":2087},"/docs/tutorials/warehouse/bigquery","GCP BigQuery",[2089,2092],{"_path":2090,"title":2091},"/docs/tutorials/transform/docker-to-slack","DockerHub webhook to Slack notification",{"_path":2093,"title":2094},"/docs/tutorials/transform/enrich-webhooks","Enrich webhooks from APIs",[2096,2099,2102,2105,2108,2111,2114,2117,2120,2123,2125,2128,2131,2134],{"_path":2097,"title":2098},"/docs/webhooks/functions/manipulating-json","JSON encoding",{"_path":2100,"title":2101},"/docs/webhooks/functions/make-http-request","Make HTTP request",{"_path":2103,"title":2104},"/docs/webhooks/functions/modify-request","Read, write request data",{"_path":2106,"title":2107},"/docs/webhooks/functions/multipart-form-data","Multipart form to JSON",{"_path":2109,"title":2110},"/docs/webhooks/functions/url-encoded-data","URL Encoded Form",{"_path":2112,"title":2113},"/docs/webhooks/functions/working-with-time","Working with time",{"_path":2115,"title":2116},"/docs/webhooks/functions/send-emails","Sending emails",{"_path":2118,"title":2119},"/docs/webhooks/functions/crypto-functions","Base64, encryption",{"_path":2121,"title":2122},"/docs/webhooks/functions/integrate-into-cicd","Integrating into CI/CD",{"_path":2124,"title":2087},"/docs/webhooks/functions/big-query",{"_path":2126,"title":2127},"/docs/webhooks/functions/accessing-metadata","Accessing metadata",{"_path":2129,"title":2130},"/docs/webhooks/functions/response-functions","Response (post-delivery) functions",{"_path":2132,"title":2133},"/docs/webhooks/functions/alerting","Alerting from functions",{"_path":2135,"title":2136},"/docs/webhooks/functions","Functions",1786379835424]