Unknown SSL protocol error in connection to bitbucket

Hi , 

From Jenkins, when connecting to Bitbucket repository using SSL, i am getting below error :

stderr: fatal: unable to access 'https://q-bitbucket.nl.eu.abnamro.com:7999/scm/sccm/sccm-manager.git/': Unknown SSL protocol error in connection to q-bitbucket.nl.eu.abnamro.com:8080

When i checked in Bitbucket settings i see : sslProtocol="TLS", should i change it to SSL ? 



3 answers

0 vote

Hi Sriram, 

Looks like you are using some reverse proxy, am I right? If so, can you confirm if your reverse proxy is recognizing your certificate? What is the output of the following command?

curl -3 -v https://q-bitbucket.nl.eu.abnamro.com:7999/scm/sccm/sccm-manager.git/

The command above you show if your server is supporting ssl v3. If not, you can try to add this for testing purposes with the following command:

openssl s_client -connect
https://q-bitbucket.nl.eu.abnamro.com:7999/scm/sccm/sccm-manager.git/ -ssl3

If you are using Reverse Proxy, please check this documentation:



Lastly, can confirm if those ports 7999 or 8080 are supporting HTTPS? This sounds like and HTTP connection.



Renato Rudnicki

Hi Renato Rudnicki, 

We are using reverse proxy ( Load Balanced as i understood).  And our rev proxy is able to recognize the certificate. I have loaded the certificate chain to a keystore (q-bitbucket_nl_eu_abnamro_com.jks) , and set this path in /var/gitstash/atlassian-bitbucket-4.1.0/conf/server.xml


Here is the output of curl command:

curl -3 -v https://q-bitbucket.nl.eu.abnamro.com:7999/scm/sccm/sccm-manager.git/
* About to connect() to q-bitbucket.nl.eu.abnamro.com port 7999
* Trying connected
* Connected to q-bitbucket.nl.eu.abnamro.com ( port 7999
* successfully set certificate verify locations:
* CAfile: /etc/pki/tls/certs/ca-bundle.crt
CApath: none
* SSLv3, TLS handshake, Client hello (1):
SSLv3, TLS alert, Server hello (2):
error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
* Closing connection #0
curl: (35) error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number


From this command , i see CA file path is showing /etc/pki/tls/certs/ca-bundle.crt , is this expected ? of should i change the path ? please suggest . 




Looks like the openssl version from your LB and your BB Server are not the same or they don’t support the same cypher version. 


You can check this with the following commands:

openssl version

openssl ciphers -v


I recommend you to setup the openssl version to the same version of your BB Server. 


I Also recommend you to check this documentation: https://confluence.atlassian.com/display/BitbucketServerKB/Securing+Bitbucket+Server+(using+Tomcat)+against+Poodle+Disabling+SSLv3




0 vote

Browsing in an unsafe and unsecured environment causes damage to System Host Files. This is also one of the reasons of getting Chrome ERR SSL PROTOCOL ERROR,  you can try to Run window, enter this carefully- C:\Windows\System32\drivers\etc.

Suggest an answer

Log in or Sign up to answer
Atlassian Community Anniversary

Happy Anniversary, Atlassian Community!

This community is celebrating its one-year anniversary and Atlassian co-founder Mike Cannon-Brookes has all the feels.

Read more
Community showcase
Piotr Plewa
Published Dec 27, 2017 in Bitbucket

Recipe: Deploying AWS Lambda functions with Bitbucket Pipelines

Bitbucket Pipelines helps me manage and automate a number of serverless deployments to AWS Lambda and this is how I do it. I'm building Node.js Lambda functions using node-lambda&nbsp...

1,747 views 1 5
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you