error:0A000126:SSL on the Proxmox web interface is an OpenSSL 3.0 unexpected EOF error. It means the TLS handshake died mid-stream. Check pveproxy logs, certs, and reverse proxy settings.

What’s happening
OpenSSL 3.0 got stricter about unexpected connection closures. When the client sends a TLS alert or the server closes early, you get error:0A000126:SSL. On Proxmox, pveproxy is the service that handles the web UI. If its cert is bad or a reverse proxy is misconfigured, the handshake fails.
Check pveproxy logs
First, look at the logs. Run:
journalctl -u pveproxy -f
Then try to load the web UI. You’ll see errors like SSL_accept: error in error or unexpected eof while reading. That confirms the server side is choking.

Check the certificate
Proxmox uses its own CA and certs in /etc/pve/local/pve-ssl.pem and /etc/pve/local/pve-ssl.key. If you uploaded your own cert, permissions might be wrong. pveproxy runs as user www-data, so the key must be readable by that user. I wrote about a similar issue with certificate ownership breaking pveproxy.
Check the cert with:
openssl x509 -in /etc/pve/local/pve-ssl.pem -text -noout
Make sure the CN or SAN matches the hostname you’re using in the browser. A mismatch can cause the client to abort the handshake.
Reverse proxy settings
If you’re using nginx or another proxy in front of Proxmox, the error might be there. The proxy needs to pass the TLS connection properly. For nginx, the proxy_ssl_server_name directive should be on, and proxy_ssl_verify off unless you’ve set up CA trust. Also check that the proxy isn’t closing the connection early because of a timeout.
Quick fix
If you just want it working, regenerate the Proxmox certs:
pvecm updatecerts -f
Then restart pveproxy:
systemctl restart pveproxy
That often clears the error if it’s a cert issue. If you’re behind a proxy, test the UI directly from the Proxmox host’s IP to isolate the problem.
Honestly, this error is annoying because it’s vague. But the fix is usually one of these three things. Don’t overthink it.