Technical

error:0A000126:SSL on Proxmox Web Interface: Fix the Unexpected EOF

error:0A000126:SSL on Proxmox Web Interface: Fix the Unexpected EOF

error:0A000126:SSL on the Proxmox web interface is an OpenSSL 3.0 unexpected EOF error. It means the TLS handshake died mid-stream. Check pveproxy logs, certs, and reverse proxy settings.

Close-up of glowing fiber optic lights with a purple and blue bokeh effect.

What’s happening

OpenSSL 3.0 got stricter about unexpected connection closures. When the client sends a TLS alert or the server closes early, you get error:0A000126:SSL. On Proxmox, pveproxy is the service that handles the web UI. If its cert is bad or a reverse proxy is misconfigured, the handshake fails.

Check pveproxy logs

First, look at the logs. Run:

journalctl -u pveproxy -f

Then try to load the web UI. You’ll see errors like SSL_accept: error in error or unexpected eof while reading. That confirms the server side is choking.

Abstract image of ethereal fiber optic strands cascading with glowing blue lights.

Check the certificate

Proxmox uses its own CA and certs in /etc/pve/local/pve-ssl.pem and /etc/pve/local/pve-ssl.key. If you uploaded your own cert, permissions might be wrong. pveproxy runs as user www-data, so the key must be readable by that user. I wrote about a similar issue with certificate ownership breaking pveproxy.

Check the cert with:

openssl x509 -in /etc/pve/local/pve-ssl.pem -text -noout

Make sure the CN or SAN matches the hostname you’re using in the browser. A mismatch can cause the client to abort the handshake.

Reverse proxy settings

If you’re using nginx or another proxy in front of Proxmox, the error might be there. The proxy needs to pass the TLS connection properly. For nginx, the proxy_ssl_server_name directive should be on, and proxy_ssl_verify off unless you’ve set up CA trust. Also check that the proxy isn’t closing the connection early because of a timeout.

Quick fix

If you just want it working, regenerate the Proxmox certs:

pvecm updatecerts -f

Then restart pveproxy:

systemctl restart pveproxy

That often clears the error if it’s a cert issue. If you’re behind a proxy, test the UI directly from the Proxmox host’s IP to isolate the problem.

Honestly, this error is annoying because it’s vague. But the fix is usually one of these three things. Don’t overthink it.

Leave a comment

Comments are reviewed before they appear. Your email is never published.