# OpenZiti Controller TLS Handshake Failure - "not handler for requested protocols \[h2 http/1.1\]"

**URL:** <https://openziti.discourse.group/t/openziti-controller-tls-handshake-failure-not-handler-for-requested-protocols-h2-http-1-1/5489>\
**Category:** General Questions\
**Created:** [January 16, 2026, 11:45am UTC](https://openziti.discourse.group/t/openziti-controller-tls-handshake-failure-not-handler-for-requested-protocols-h2-http-1-1/5489 "2026-01-16T11:45:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![andhika.ridwan](https://avatars.discourse-cdn.com/v4/letter/a/bbe5ce/32.png) [@andhika.ridwan](https://openziti.discourse.group/u/andhika.ridwan)\
**Post date:** [January 16, 2026, 11:45am UTC](https://openziti.discourse.group/t/openziti-controller-tls-handshake-failure-not-handler-for-requested-protocols-h2-http-1-1/5489/1 "2026-01-16T11:45:37Z")

</div>

Environment: - OpenZiti v1.6.12 - Ubuntu 24.04 LTS - Controller running on port 6262 Problem: Edge API TLS listener rejecting standard HTTP/1.1 connections. Error: "not handler for requested protocols [h2 http/1.1]" Details: - Certificate chain is valid (generated with proper EKU: TLS Web Server Authentication) - Subject Alternative Names correct (localhost, internal IPs, siti.myrepublic.net.id) - Key Usage extensions correct - But TLS handshake fails with EOF errors Curl test result: curl -k [https://127.0.0.1:6262/version](https://127.0.0.1:6262/version) → error:0A000438:SSL routines::tlsv1 alert internal error Controller logs: {"\_context":"tls:0.0.0.0:6262","error":"not handler for requested protocols [h2 http/1.1]"...} Question: How to configure OpenZiti controller edge API to accept standard HTTPS/HTTP1.1 connections? Or is there a different protocol/configuration required?

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 16, 2026, 8:49pm UTC](https://openziti.discourse.group/t/openziti-controller-tls-handshake-failure-not-handler-for-requested-protocols-h2-http-1-1/5489/2 "2026-01-16T20:49:25Z")

</div>

Hi @andhika.ridwan, I'm sorry but I don't understand what you've done here and what you're trying to do.

If you're generating your own certificate chain, you really need to understand that process fully. There are discourse posts that have discussed this in the past. See this thread from just last month, it might help you?

> [@Router enrollment fails with "token signature is invalid" - JWT kid vs EST cacerts mismatch](https://openziti.discourse.group/t/router-enrollment-fails-with-token-signature-is-invalid-jwt-kid-vs-est-cacerts-mismatch/5394/2):
>
> Hi @jfin, welcome to the community and to OpenZiti Not gonna lie - this line does scare me as someone trying to support the community. Getting the PKI right is a difficult thing to do and not for the faint of heart. I expect you've misconfigured it somehow. Also this statement at the end of your post is incorrect. \*Quickstart works because it uses internal enrollment that bypasses external JWT verification.\*. That is not true, don't be misled... I'd suggest you read through this older thread [O…](https://openziti.discourse.group/t/openziti-network-from-scratch/2168/10)

Other than that, I'm not exactly sure how to help with what you've posted/asked so far
