You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HTTPS站点使用CloudFlare CDN时的SSL配置及证书相关咨询

Cloudflare SSL with Existing Server HTTPS: Your Questions Answered

Hey there, let's clear up these common questions about using Cloudflare alongside your existing HTTPS setup—this stuff can get tricky at first, but it's straightforward once you break down the flow.

1. Should you enable Cloudflare's SSL option?

Absolutely—you need to enable this to keep the end-to-end HTTPS experience secure for your users. Cloudflare offers several SSL modes, and choosing the right one matters:

  • Flexible: Only encrypts the connection between users and Cloudflare (user ↔ Cloudflare is HTTPS, Cloudflare ↔ your server is HTTP). This is the least secure option and not recommended unless you have no choice, since backend traffic is unencrypted.
  • Full: Encrypts both legs of the connection (user ↔ Cloudflare is HTTPS, Cloudflare ↔ your server is HTTPS). This uses your server's existing SSL certificate, though Cloudflare doesn't validate if that certificate is trusted (self-signed works here, but a trusted certificate is still better).
  • Full (strict): The most secure option—same as Full, but Cloudflare requires your server's SSL certificate to be valid and trusted by a public CA. This is the mode you should aim for if your server already has a proper HTTPS certificate.

Enabling Cloudflare's SSL ensures users see the padlock in their browsers and avoid security warnings.

2. Which SSL certificate does the user's browser load?

When you enable Cloudflare's SSL, the browser will load Cloudflare's SSL certificate for the connection between the user and Cloudflare's edge node. This is typically Cloudflare's free Universal SSL certificate, which they issue automatically when you add your domain.

The connection between Cloudflare and your origin server uses a different certificate, depending on the SSL mode you pick:

  • For Flexible mode: No encryption here—traffic is sent over unencrypted HTTP.
  • For Full/Full (strict) mode: Cloudflare uses your origin server's existing SSL certificate to encrypt traffic between itself and your server.

3. Should you disable SSL on your origin server?

No, do NOT disable SSL on your origin server—especially if you're using Full or Full (strict) mode. Cloudflare needs to establish an HTTPS connection to your server in those modes, so your server's SSL certificate must remain active and valid.

Even if you were to use Flexible mode (which we don't recommend), keeping SSL enabled on your server is still a good idea—you might switch to a more secure mode later, or someone could access your server directly bypassing Cloudflare.

Quick Recap of the SSL Flow with Cloudflare

To make it crystal clear, here's how encryption works end-to-end:

  1. User's browser connects to Cloudflare's edge node using Cloudflare's SSL certificate (HTTPS).
  2. Cloudflare forwards the request to your origin server—this connection is either HTTP (Flexible) or HTTPS using your server's certificate (Full/Full strict).
  3. Your server sends the response back to Cloudflare, which relays it to the user over the encrypted connection.

内容的提问来源于stack exchange,提问作者KK1850

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:12:02