TLS Certificate Issues, cannot connect to PVE Interface error:0A000126:SSL

Flavinux

Renowned Member
Jan 23, 2017
4
0
66
41
Hello,
i encounter some difficulty, I'm ussing smallstep PKI, Certificate generate via ACME or CLI, none of certificate works with pveproxy .
proxmox 8.x & version 9.2.20 same problem


Code:
# pveproxy start --debug
2026-10-03 18:19:09.349072 worker[1658055]: PVE::APIServer::AnyEvent +1937: (eval): ACCEPT FH10 CONN1
2026-10-03 18:19:09.349072 worker[1658056]: PVE::APIServer::AnyEvent +1937: (eval): ACCEPT FH10 CONN1
2026-10-03 18:19:09.349168 worker[1658055]: PVE::APIServer::AnyEvent +1937: (eval): Setting TLS to autostart
2026-10-03 18:19:09.349170 worker[1658056]: PVE::APIServer::AnyEvent +1937: (eval): Setting TLS to autostart
2026-10-03 18:19:09.350017 worker[1658056]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: close connection AnyEvent::Handle=HASH(0x62340a4fd900)
2026-10-03 18:19:09.350017 worker[1658055]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: close connection AnyEvent::Handle=HASH(0x62340a4fd900)
2026-10-03 18:19:09.350082 worker[1658056]: PVE::APIServer::AnyEvent +178: __ANON__: CLOSE FH10
2026-10-03 18:19:09.350082 worker[1658055]: PVE::APIServer::AnyEvent +178: __ANON__: CLOSE FH10
2026-10-03 18:19:09.350150 worker[1658056]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: DISCONNECT CONN0
2026-10-03 18:19:09.350153 worker[1658055]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: DISCONNECT CONN0
2026-10-03 18:19:09.369257 worker[1658056]: PVE::APIServer::AnyEvent +1937: (eval): ACCEPT FH10 CONN1
2026-10-03 18:19:09.369257 worker[1658057]: PVE::APIServer::AnyEvent +1937: (eval): ACCEPT FH10 CONN1
2026-10-03 18:19:09.369315 worker[1658056]: PVE::APIServer::AnyEvent +1937: (eval): Setting TLS to autostart
2026-10-03 18:19:09.369316 worker[1658057]: PVE::APIServer::AnyEvent +1937: (eval): Setting TLS to autostart
2026-10-03 18:19:09.369767 worker[1658056]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: close connection AnyEvent::Handle=HASH(0x62341101f690)
2026-10-03 18:19:09.369767 worker[1658057]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: close connection AnyEvent::Handle=HASH(0x62341102cef0)
2026-10-03 18:19:09.369819 worker[1658056]: PVE::APIServer::AnyEvent +178: __ANON__: CLOSE FH10
2026-10-03 18:19:09.369819 worker[1658057]: PVE::APIServer::AnyEvent +178: __ANON__: CLOSE FH10
2026-10-03 18:19:09.369870 worker[1658056]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: DISCONNECT CONN0
2026-10-03 18:19:09.369873 worker[1658057]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: DISCONNECT CONN0

Code:
openssl s_client -connect pve.domain.tld:8006 -showcerts
Connecting to 2001:0DB8::174
CONNECTED(00000003)
805784DB457D0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:698:
---
no peer certificate available
---
No client certificate CA names sent
Negotiated TLS1.3 group: <NULL>
---
SSL handshake has read 0 bytes and written 1580 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Protocol: TLSv1.3
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
Code:
With curl:
curl -v -k https://pve.domain.tld:8006/
* Host pve.domain.tld:8006 was resolved.
* IPv6: 2001:0DB8::174
* IPv4: 192.168.0.174
*   Trying [2001:0DB8::174]:8006...
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (OUT), TLS alert, decode error (562):
* TLS connect error: error:0A000126:SSL routines::unexpected eof while reading
* closing connection #0

Code:
pveversion -v
proxmox-ve: 9.2.0 (running kernel: 7.0.14-16-pve)
pve-manager: 9.2.20 (running version: 9.2.20/49318c671b82f31e)
proxmox-kernel-helper: 9.2.0
proxmox-kernel-7.0.14-19-pve-signed: 7.0.14-19
proxmox-kernel-7.0: 7.0.14-19
proxmox-kernel-7.0.14-16-pve-signed: 7.0.14-16
proxmox-kernel-7.0.14-15-pve-signed: 7.0.14-15
proxmox-kernel-7.0.14-14-pve-signed: 7.0.14-14
pve-kernel-5.11: 7.0-10
proxmox-kernel-6.8.12-43-pve-signed: 6.8.12-43
proxmox-kernel-6.8: 6.8.12-43
proxmox-kernel-6.8.12-41-pve-signed: 6.8.12-41
proxmox-kernel-6.5.13-6-pve-signed: 6.5.13-6
proxmox-kernel-6.5: 6.5.13-6
pve-kernel-5.13.19-2-pve: 5.13.19-4
pve-kernel-5.11.22-7-pve: 5.11.22-12
pve-kernel-5.11.22-1-pve: 5.11.22-2
ceph-fuse: 19.2.6-pve4
corosync: 3.1.10-pve3
criu: 4.1.1-1
frr-pythontools: 10.6.1-1+pve3
ifupdown2: 3.3.0-1+pmx12
intel-microcode: 3.20251111.1~deb13u1
ksm-control-daemon: 1.5-1
libjs-extjs: 7.0.0-7
libproxmox-acme-perl: 1.7.2
libproxmox-backup-qemu0: 2.0.3
libproxmox-rs-perl: 0.4.1
libpve-access-control: 9.1.2
libpve-apiclient-perl: 3.4.3
libpve-cluster-api-perl: 9.1.6
libpve-cluster-perl: 9.1.6
libpve-common-perl: 9.2.2
libpve-guest-common-perl: 6.0.5
libpve-http-server-perl: 6.0.5
libpve-network-perl: 1.6.7
libpve-notify-perl: 9.1.6
libpve-rs-perl: 0.15.3
libpve-storage-perl: 9.1.10
libspice-server1: 0.15.2-1+b1
lvm2: 2.03.31-2+pmx1
lxc-pve: 7.0.0-2
lxcfs: 7.0.0-pve1
novnc-pve: 1.7.0-2
openvswitch-switch: 3.5.0-1+b1
proxmox-backup-client: 4.2.6-1
proxmox-backup-file-restore: 4.2.6-1
proxmox-backup-restore-image: 1.0.0
proxmox-enterprise-support-keyring: 1.1
proxmox-firewall: 1.2.3
proxmox-kernel-helper: 9.2.0
proxmox-mail-forward: 1.0.3
proxmox-mini-journalreader: 1.7
proxmox-offline-mirror-helper: 0.7.4
proxmox-widget-toolkit: 5.2.10
pve-cluster: 9.1.6
pve-container: 6.1.14
pve-docs: 9.2.12
pve-edk2-firmware: 4.2026.08-1
pve-esxi-import-tools: 1.0.1
pve-firewall: 6.0.6
pve-firmware: 3.18-6
pve-ha-manager: 5.2.5
pve-i18n: 3.10.0
pve-qemu-kvm: 11.0.3-3
pve-xtermjs: 6.0.0-2
qemu-server: 9.2.8
smartmontools: 7.5-pve2
spiceterm: 3.4.2
swtpm: 0.8.0+pve3
vncterm: 1.9.2
zfsutils-linux: 2.4.4-pve1

I try to adapt some x509 Extensions to certificate and nothing change. I'm stuck

I Looked for similar error, MTU is default(1500), for the second param with ACME.pm patch, and to others interfaces, i got exactly same problem.
Certificate generated are validated with openssl verify and works with others nginx ssl app.

Any Suggestions?
Thanks in advance,

Flavinux
 
Could the following thread be relevant to this issue?


Although the root cause may be different, this thread reports a similar issue where the Web GUI became inaccessible after installing a certificate, with the following error:

Code:
error:0A000126: SSL routines::unexpected eof while reading

Could you also run the following command and share the output?

Code:
journalctl -b -u pveproxy | tail -n 200

Please redact any sensitive information before posting.
 
Hello, Thanks for the answer
I have the same issue if certificate is provided via acme protocol than added privkey & certificate chain from the interface.
Here the query from pve interface :
Code:
Loading ACME account details
Placing ACME orderOrder 
URL: https://cert.domain.tld/acme/acme/order/2180RpNszfKChrMg5jAh4usF3YEzweZ9

Getting authorization details from 'https://cert.domain.tld/acme/acme/auth/5H3Y9iVvjHY2ZXmUMquIveFKGv6iqZL'
The validation for doublehype.domain.tld is pending!
Setting up webserver
Triggering validationSleeping for 5 seconds
tatus is 'valid', domain 'doublehype.domain.tld' OK!

All domains validated!

Creating CSR
Checking order status
Order is ready, finalizing order
valid!

Downloading certificate
Setting pveproxy certificate and key
Restarting pveproxy
TASK OK
journalctl -b -u pveproxy | tail -n 200 :
Code:
Oct 04 16:03:39 doublehype systemd[1]: Stopping pveproxy.service - PVE API Proxy Server...
Oct 04 16:03:41 doublehype pveproxy[1683239]: received signal TERM
Oct 04 16:03:41 doublehype pveproxy[1683239]: server closing
Oct 04 16:03:41 doublehype pveproxy[168121]: worker exit
Oct 04 16:03:41 doublehype pveproxy[168122]: worker exit
Oct 04 16:03:41 doublehype pveproxy[168120]: worker exit
Oct 04 16:03:41 doublehype pveproxy[1683239]: worker 168122 finished
Oct 04 16:03:41 doublehype pveproxy[1683239]: worker 168120 finished
Oct 04 16:03:41 doublehype pveproxy[1683239]: worker 168121 finished
Oct 04 16:03:41 doublehype pveproxy[1683239]: server stopped
Oct 04 16:03:42 doublehype systemd[1]: pveproxy.service: Deactivated successfully.
Oct 04 16:03:42 doublehype systemd[1]: Stopped pveproxy.service - PVE API Proxy Server.
Oct 04 16:03:42 doublehype systemd[1]: pveproxy.service: Consumed 13min 24.456s CPU time, 574.2M memory peak.
Oct 04 16:03:42 doublehype systemd[1]: Starting pveproxy.service - PVE API Proxy Server...
Oct 04 16:03:44 doublehype pveproxy[169561]: starting server
Oct 04 16:03:44 doublehype pveproxy[169561]: starting 3 worker(s)
Oct 04 16:03:44 doublehype pveproxy[169561]: worker 169562 started
Oct 04 16:03:44 doublehype pveproxy[169561]: worker 169563 started
Oct 04 16:03:44 doublehype pveproxy[169561]: worker 169564 started
Oct 04 16:03:44 doublehype systemd[1]: Started pveproxy.service - PVE API Proxy Server.
Oct 04 16:04:25 doublehype systemd[1]: Reloading pveproxy.service - PVE API Proxy Server...
Oct 04 16:04:26 doublehype pveproxy[170460]: send HUP to 169561
Oct 04 16:04:26 doublehype pveproxy[169561]: received signal HUP
Oct 04 16:04:26 doublehype pveproxy[169561]: server closing
Oct 04 16:04:26 doublehype pveproxy[169561]: server shutdown (restart)
Oct 04 16:04:26 doublehype systemd[1]: Reloaded pveproxy.service - PVE API Proxy Server.
Oct 04 16:04:28 doublehype pveproxy[169561]: Using '/etc/pve/local/pveproxy-ssl.pem' as certificate for the web interface.
Oct 04 16:04:28 doublehype pveproxy[169561]: restarting server
Oct 04 16:04:28 doublehype pveproxy[169561]: starting 3 worker(s)
Oct 04 16:04:28 doublehype pveproxy[169561]: worker 170478 started
Oct 04 16:04:28 doublehype pveproxy[169561]: worker 170479 started
Oct 04 16:04:28 doublehype pveproxy[169561]: worker 170480 started
Oct 04 16:04:33 doublehype pveproxy[169562]: worker exit
Oct 04 16:04:33 doublehype pveproxy[169563]: worker exit
Oct 04 16:04:33 doublehype pveproxy[169561]: worker 169563 finished
Oct 04 16:04:33 doublehype pveproxy[169561]: worker 169562 finished
Oct 04 16:04:33 doublehype pveproxy[169561]: worker 169564 finished
Oct 04 16:04:34 doublehype pveproxy[170677]: worker exit

There is for me no revelent informatiation, i supposed there is missing information inside certificate
Certificate Authority and intermediate certificate Authority are installed in certificate os "database" ( via update-ca-certificates)

it seems to be valid:
Code:
openssl verify pveproxy-ssl.pem
pveproxy-ssl.pem: OK
X509v3 extensions:
Code:
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment
            X509v3 Extended Key Usage:
                TLS Web Server Authentication
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Subject Key Identifier:
                9F:C6:E5:A6:42:D5:65:24:--:80:4C:52:92:E4:54:DE:07:7E:C3
            X509v3 Authority Key Identifier:
                8C:0F:64:2A:38:F4:03:73:--:D2:BA:D0:D7:28:43:BF:22:C1:57
            Authority Information Access:
                CA Issuers - URI:https://cert.domain.tld/intermediates.pem
            X509v3 Subject Alternative Name:
                DNS:doublehype.domain.tld
            X509v3 CRL Distribution Points:
                Full Name:
                  URI:https://cert.domain.tld/crl
            1.3.6.1.4.1.37476.9000.64.1:
                0......acme..
    Signature Algorithm: ecdsa-with-SHA256
    Signature Value:
Thanks in advance,

Flav
 
Thank you for the information.

There do not appear to be any certificate-loading errors in the logs.

To isolate the issue, I would like to test the TLS connection directly against pveproxy from the PVE host itself. Connecting to 127.0.0.1 bypasses DNS resolution and external network devices, such as firewalls and reverse proxies.

Could you please run the following command on the PVE host and share the output?

Code:
openssl s_client -connect 127.0.0.1:8006 -servername doublehype.domain.tld -showcerts

This will help determine whether pveproxy itself can complete the TLS handshake and present the certificate chain correctly.

Please redact any sensitive information before sharing the output.
 
I got exactly same issue no tls handshake (read)
Code:
openssl s_client -connect 127.0.0.1:8006 -servername doublehype.domain.tld -showcerts
Connecting to 127.0.0.1
CONNECTED(00000003)
80A7A924BA7D0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:698:
---
no peer certificate available
---
No client certificate CA names sent
Negotiated TLS1.3 group: <NULL>
---
SSL handshake has read 0 bytes and written 1580 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Protocol: TLSv1.3
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---

Flav
 
Since the same issue also occurs when connecting directly to 127.0.0.1, this suggests that DNS and external network devices are less likely to be the cause.

Could you check whether the certificate and private key match by running the following commands?

Code:
openssl x509 -in /etc/pve/local/pveproxy-ssl.pem -pubkey -noout | openssl pkey -pubin -outform DER | sha256sum
openssl pkey -in /etc/pve/local/pveproxy-ssl.key -pubout -outform DER | sha256sum

The SHA-256 hashes produced by these two commands should be identical.

Could you also share the output of the following command to check whether the private key can be read successfully and is internally consistent?

Code:
openssl pkey -in /etc/pve/local/pveproxy-ssl.key -check -noout

These commands only perform checks and do not modify the certificate or private key. There is no need to reproduce the issue while running them.

Please do not share the private key itself.