Skip to content
Cloudflare Docs logomark
Cloudflare
Docs
SSL/TLS
Navigation menu icon
Open external link
Cloudflare Docs logomark
Cloudflare
Docs
SSL/TLS
Dropdown icon
SSL/TLS menu
Cloudflare homepage
Overview
Get started
Expand: Edge certificates
Edge certificates
Expand: Universal SSL
Universal SSL
Enable Universal SSL certificates
Disable Universal SSL certificates
Limitations
Troubleshooting
Expand: Advanced certificates
Advanced certificates
Manage advanced certificates
API commands
Expand: Custom certificates
Custom certificates
Manage custom certificates
Renewing
Bundle methodologies
Add CAA records
Remove key file password
Enforce HTTPS connections
Expand: Domain Control Validation (DCV)
Domain Control Validation (DCV)
Expand: Methods
Methods
TXT
Email
HTTP
Troubleshooting
Staging environment (Beta)
Backup certificates
Expand: Additional options
Additional options
Certificate Transparency Monitoring
HTTP Strict Transport Security (HSTS)
Certificate Signing Requests (CSRs)
TLS 1.3
Minimum TLS Version
Automatic HTTPS Rewrites
Always Use HTTPS
Opportunistic Encryption
Expand: Client certificates
Client certificates
Create a client certificate
Configure your mobile app or IoT device
Enable mTLS
Revoke a client certificate
Troubleshooting
Expand: Keyless SSL
Keyless SSL
Get started
Expand: Hardware security modules
Hardware security modules
Configuration
AWS cloud HSM
Azure Dedicated HSM
Azure Managed HSM
SoftHSMv2
Entrust nShield Connect
IBM cloud HSM
Google Cloud HSM
Upgrade your key server
Expand: Reference
Reference
High availability
Scaling and benchmarking
Keyless delegation
Troubleshooting
Mutual authentication
Expand: Origin server
Origin server
Expand: Encryption modes
Encryption modes
Off (no encryption)
Flexible
Full
Full (strict)
Strict (SSL-Only Origin Pull)
Cipher suites
Origin CA certificates
SSL/TLS Recommender
Expand: Authenticated origin pull
Authenticated origin pull
How authenticated origin pulls work
Set up authenticated origin pulls
Custom origin trust store
SSL for SaaS
External link icon
Open external link
Expand: Reference
Reference
Expand: Cipher suites
Cipher suites
Recommendations
Supported cipher suites
Customize cipher suites
Compliance status
Custom certificates
Match on origin
Troubleshooting
TLS protocols
Certificate and hostname priority
Certificate authorities
Browser compatibility
Expand: Migration guides
Migration guides
Changes to HTTP DCV
Expand: Digicert update
Digicert update
Universal certificates
Custom hostnames
Certificate pinning
Certificate statuses
Validation backoff schedule
Validity periods
FAQs
Search icon (depiction of a magnifying glass)
/
Give Feedback
GitHub icon
Visit SSL/TLS on GitHub
Light theme icon (depiction of a sun)
Dark theme icon (depiction of a moon)
Set theme to dark (⇧+D)
Migration guides
Changes to HTTP DCV
Digicert update