This FAQ lists common Nginx errors as they appear in the Nginx error log, with the cause and a fix for each.
The first entry is SSL_do_handshake() failed on a proxy server, which is fixed by adding proxy_ssl_server_name on; so Nginx passes the server name through the TLS SNI extension.
Each solution links to the Nginx documentation where possible.
This guide is a living document and is constantly updated.
Error while SSL handshaking in Nginx
This is a common issue for proxy servers. You might encounter a following error in the Nginx error log:
SSL_do_handshake() failed (SSL: error:14201044:SSL routines:tls_choose_sigalg:internal error) while SSL handshaking, client: 1.2.3.4, server: 0.0.0.0:443)
Solution to SSL_do_handshake() failed with Nginx proxy
Simply enable passing of the server name through TLS Server Name Indication extension (SNI) in the proxy server config section:
proxy_ssl_server_name on;
Example server config snippet:
# file: /etc/nginx/sites-available/{YOUR_WEBSITE}
location / {
proxy_pass http://127.0.0.1:4000;
# Add next line
proxy_ssl_server_name on;
# Rest of the config
}
Read more about proxy_ssl_server_name in the Nginx documentation.
Frequently asked questions
Nginx errors
How do I fix SSL_do_handshake() failed in Nginx?
The error SSL_do_handshake() failed (SSL: error:14201044:SSL routines:tls_choose_sigalg:internal error) while SSL handshaking is common on Nginx proxy servers. Fix it by adding the proxy_ssl_server_name on directive to the location block that holds proxy_pass. Nginx then passes the server name through the TLS Server Name Indication (SNI) extension.
What does proxy_ssl_server_name do in Nginx?
The proxy_ssl_server_name directive enables passing of the server name through the TLS Server Name Indication (SNI) extension when Nginx proxies a request. Turning it on resolves SSL handshake failures such as tls_choose_sigalg:internal error on proxy servers.
Where do I put proxy_ssl_server_name in the Nginx config?
Add proxy_ssl_server_name on inside the location block of your site config, for example in /etc/nginx/sites-available/{YOUR_WEBSITE}, next to the proxy_pass directive. Keep the rest of the location config unchanged.