SSL server handshake failure - cpp:3019
From Tech-Wiki
More actions
Historical Blue Coat ProxySG workaround for a specific SSL proxy handshake failure.
Legacy / version-specific guidance
ProxySG policy syntax and product behaviour are version-specific. Disabling protocol detection is a security-relevant bypass and is not a general TLS fix.
Validation status
Reviewed during the Tech-Wiki Wave 3 migration on 27 September 2026. The historical procedure is retained for engineers supporting older estates, but is not presented as the default approach for a new deployment.
Security inspection bypass
The historical workaround uses detect_protocol(none). Validate the actual protocol/TLS problem and current Broadcom guidance before bypassing detection.
Historical procedure
Error on the Bluecoats. The following message is found in bluecoat event log:
"SSL server handshake failure" 0 300000:1 sslproxy_worker.cpp:3019"
This is caused by protocol violation and the Bluecoat drops the connection. The solution is to add the site to the local file add the following command:
url.domain=xxxxxxx.com detect_protocol(none)