SSL between Cloudflare and the Origin

Full (strict) only after the origin has a certificate of its own.

The browser can show a valid Cloudflare cert while the VPS has none. Flexible hides that. We put a real certificate on the server and leave Flexible off.

The three modes

What the orange cloud is actually doing

Flexible

Cloudflare talks HTTP to the origin. A redirect to HTTPS on the server then loops. We do not leave a production site here.

Full

Encrypts to the origin and accepts any certificate, including an expired one. Better than Flexible. Not the setting we stop on.

Full (strict)

The origin certificate must be valid for the name. Let’s Encrypt or a Cloudflare origin cert, then the firewall limited to Cloudflare ranges so the old IP is not a bypass.

Not this page

A renewal with no Cloudflare in front is the other SSL page

Certbot failing on a bare VPS is a DNS or port 80 problem. This page is the hop between Cloudflare and the origin. Mail records stay unproxied either way. Proxying the MX is not an SSL fix.

Let’s Encrypt on the server → · Cloudflare and DNS →

Price

€55 an hour. The Cloudflare login stays yours.

Minimum 1 hour. We ask for a temporary member on the account, not the owner password. You remove it when strict mode answers without a loop.

Pricing →

Redirect loop, or Flexible left on after the move?

Tell us the domain and the SSL mode you see in Cloudflare. No owner password in the first message.

Request Support → Contact Us