← Cloudflare SSL/TLS / ssl
Cloudflare SSL/TLS
Encrypt your web traffic to prevent data theft and other tampering.
SSL/TLS certificates encrypt traffic between visitors and your website, preventing eavesdropping and data tampering. Because Cloudflare sits between your visitors and your origin server, two certificates can be involved in a single request: an edge certificate (visitor to Cloudflare) and an origin certificate (Cloudflare to your server).
Cloudflare automatically issues free certificates through Universal SSL and offers additional options for custom certificate management. Refer to Get started to set up SSL/TLS for your domain.
Features
Universal SSL covers your apex domain and first-level subdomains. Total TLS extends that coverage by automatically issuing certificates for proxied hostnames at any subdomain level.
Before issuing a certificate, a certificate authority (CA) must verify you control the domain. If you manage DNS outside of Cloudflare, you can delegate this verification to Cloudflare so certificate renewals happen automatically.
Specify the minimum TLS version that visitors must use to connect to your website or application, and restrict cipher suites to meet compliance or security requirements.
Related products
When you use Cloudflare DNS, all DNS queries for your domain are answered by Cloudflare's global anycast network. This network delivers performance and global availability.
Cloudflare for SaaS allows you to extend the security and performance benefits of Cloudflare's network to your customers via their own custom or vanity domains.
Contents
137 pages mirrored from the Cloudflare documentation for ssl.
Pages
- Client certificates (mTLS)
- Concepts
- Edge certificates
- SSL/TLS FAQ
- Get started
- Keyless SSL
- Origin server
- Post-quantum cryptography (PQC)
- Reference
- Cloudflare for SaaS
- Troubleshooting
Client certificates (mTLS)
- Bring your own CA for mTLS
- Client certificate variables
- Configure your mobile app or IoT device
- Create a client certificate
- Enable mTLS
- Forward certificate to server
- Label client certificates
- Revoke a client certificate
- Troubleshooting
- mTLS for Zero Trust
Edge certificates
- Additional options
- Always Use HTTPS
- Automatic HTTPS Rewrites
- Certificate Signing Requests (CSRs)
- Certificate Transparency Monitoring
- Cipher suites
- Compliance standards
- Customize cipher suites
- Customize cipher suites via API
- Customize cipher suites via dashboard
- Security levels
- Supported cipher suites
- Troubleshooting
- HTTP Strict Transport Security (HSTS)
- Minimum TLS Version
- Opportunistic Encryption
- TLS 1.3
- Total TLS
- Enable
- Error messages
- Advanced certificates
- API commands
- Manage advanced certificates
- Backup certificates
- Add CAA records
- Domain control validation (DCV)
- Domain control validation flow
- Methods
- Delegated
- HTTP
- TXT
- Troubleshooting
- Validation backoff schedule
- Custom certificates
- Bundle methodologies
- Remove key file password
- Renewal and expiration
- Troubleshooting
- Manage custom certificates
- ECH Protocol
- Enforce HTTPS connections
- Geo Key Manager
- Setup
- Supported options
- Staging environment
- Universal SSL
- Alerts
- Disable Universal SSL certificates
- Enable Universal SSL certificates
- Limitations
- Troubleshooting
Keyless SSL
- Get started
- Cloudflare Tunnel
- Public DNS
- Run with Docker
- Glossary
- Hardware security modules
- AWS cloud HSM
- Azure Dedicated HSM
- Azure Managed HSM
- Configuration
- Entrust nShield Connect
- Fortanix Data Security Manager
- Google Cloud HSM
- IBM Cloud HSM
- SoftHSMv2
- Reference
- High availability
- Keyless delegation
- Key server metrics
- Scaling and benchmarking
- Troubleshooting
- Upgrade your key server
Origin server
- Authenticated Origin Pulls (mTLS)
- AWS integration
- About
- Setup
- Global
- Manage certificates
- Per-hostname
- Roll back per-hostname AOP
- Zone-level
- Automatic key exchange to origins
- Cipher suites
- Custom Origin Trust Store
- Cloudflare origin CA
- Troubleshooting Cloudflare origin CA
- Encryption modes
- Flexible
- Full
- Full (strict)
- Off (no encryption)
- Strict (SSL-Only Origin Pull)
- SSL/TLS Recommender
Post-quantum cryptography (PQC)
- Post-quantum cryptography in Cloudflare One
- PQC in Cloudflare products
- PQC support
- Post-quantum between Cloudflare and origin servers
Reference
- Browser compatibility
- Certificate and hostname priority
- Certificate authorities
- Certificate pinning
- Rotate ACM certificate packs
- Certificate statuses
- Validity periods and renewal
- Cloudflare and CVE-2019-1559
- PCI compliance and vulnerabilities mitigation
- Migration guides
- DigiCert Legacy Root (G1) distrust by major browsers
- Entrust distrust by major browsers
- TLS protocols