This FAQ lists common Nginx errors as they appear in the Nginx error log, with the cause and a fix for each. The first entry is SSL_do_handshake() failed on a proxy server, which is fixed by adding proxy_ssl_server_name on; so Nginx passes the server name through the TLS SNI extension. Each solution links to the Nginx documentation where possible.

This guide is a living document and is constantly updated.

Error while SSL handshaking in Nginx

This is a common issue for proxy servers. You might encounter a following error in the Nginx error log:

SSL_do_handshake() failed (SSL: error:14201044:SSL routines:tls_choose_sigalg:internal error) while SSL handshaking, client: 1.2.3.4, server: 0.0.0.0:443)

Solution to SSL_do_handshake() failed with Nginx proxy

Simply enable passing of the server name through TLS Server Name Indication extension (SNI) in the proxy server config section:

proxy_ssl_server_name on;

Example server config snippet:

# file: /etc/nginx/sites-available/{YOUR_WEBSITE}
location / {
    proxy_pass http://127.0.0.1:4000;
     # Add next line
    proxy_ssl_server_name on;
    # Rest of the config
}

Read more about proxy_ssl_server_name in the Nginx documentation.

Frequently asked questions

Nginx errors

How do I fix SSL_do_handshake() failed in Nginx?

The error SSL_do_handshake() failed (SSL: error:14201044:SSL routines:tls_choose_sigalg:internal error) while SSL handshaking is common on Nginx proxy servers. Fix it by adding the proxy_ssl_server_name on directive to the location block that holds proxy_pass. Nginx then passes the server name through the TLS Server Name Indication (SNI) extension.

What does proxy_ssl_server_name do in Nginx?

The proxy_ssl_server_name directive enables passing of the server name through the TLS Server Name Indication (SNI) extension when Nginx proxies a request. Turning it on resolves SSL handshake failures such as tls_choose_sigalg:internal error on proxy servers.

Where do I put proxy_ssl_server_name in the Nginx config?

Add proxy_ssl_server_name on inside the location block of your site config, for example in /etc/nginx/sites-available/{YOUR_WEBSITE}, next to the proxy_pass directive. Keep the rest of the location config unchanged.

Share