
What Is a Cloudflare Origin Certificate?
A Cloudflare Origin Certificate is a free SSL certificate issued by Cloudflare specifically for securing the connection between Cloudflare's edge network and your origin server. Unlike certificates from public CAs like Let's Encrypt, a Cloudflare Origin Certificate is only trusted by Cloudflare — if users connect directly to your server bypassing Cloudflare, browsers will display a "certificate not trusted" warning.
When used correctly behind Cloudflare with SSL Mode set to "Full (Strict)", an Origin Certificate secures both legs of the connection: visitor → Cloudflare (via Cloudflare's Universal SSL) and Cloudflare → your server (via the Origin Certificate). This is the recommended configuration for maximum security.
Understanding Cloudflare SSL Modes
Before installing an Origin Certificate, understand the four Cloudflare SSL modes:
- Off — No SSL at all. All traffic is unencrypted HTTP. Never use this.
- Flexible — HTTPS between visitor and Cloudflare, but Cloudflare connects to your server over HTTP. Data between Cloudflare and your server is unencrypted. Not recommended.
- Full — Encrypts both legs but does not validate your server's certificate (accepts self-signed certs). Better than Flexible.
- Full (Strict) — Encrypts both legs and validates your server's certificate. Requires a valid Origin Certificate or trusted SSL on your server. This is the recommended mode.
Goal: Enable SSL Mode "Full (Strict)" on Cloudflare, then install the Origin Certificate on your server. Follow the steps below to achieve this configuration.
Step 1 — Generate a Cloudflare Origin Certificate
In Cloudflare Dashboard, navigate to SSL/TLS → Origin Server:
- Click "Create Certificate"
- Choose "Generate private key and CSR with Cloudflare" (simplest) or "Use my own private key and CSR"
- Specify hostnames — e.g.,
example.comand*.example.com - Select certificate validity (15 years recommended for origins since renewal requires reinstallation)
- Click "Create"
Cloudflare generates the Origin Certificate and Private Key. Save both files immediately — the Private Key will not be shown again.
Step 2 — Save Certificate Files on Your Server
mkdir -p /etc/ssl/cloudflare
nano /etc/ssl/cloudflare/cert.pem # paste Origin Certificate
nano /etc/ssl/cloudflare/key.pem # paste Private Key
chmod 644 /etc/ssl/cloudflare/cert.pem
chmod 600 /etc/ssl/cloudflare/key.pem
Step 3A — Install on Nginx
server {
listen 443 ssl http2;
server_name example.com;
ssl_certificate /etc/ssl/cloudflare/cert.pem;
ssl_certificate_key /etc/ssl/cloudflare/key.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
# ... your site configuration ...
}
server {
listen 80;
server_name example.com;
return 301 https://$host$request_uri;
}
nginx -t && systemctl reload nginx
Step 3B — Install on Apache
<VirtualHost *:443>
ServerName example.com
SSLEngine on
SSLCertificateFile /etc/ssl/cloudflare/cert.pem
SSLCertificateKeyFile /etc/ssl/cloudflare/key.pem
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
SSLCipherSuite HIGH:!aNULL:!MD5
# ... DocumentRoot and other directives ...
</VirtualHost>
apachectl configtest && systemctl reload apache2
Step 4 — Set SSL Mode to Full (Strict) on Cloudflare
Return to Cloudflare Dashboard → SSL/TLS → Overview and select "Full (Strict)". This is the most critical step — without it, Cloudflare may still connect to your origin over HTTP regardless of your certificate installation.
Warning: Before switching to Full (Strict), confirm the Origin Certificate is correctly installed on your server. Switching to this mode without a valid server certificate will immediately break your site.
Step 5 — Download Cloudflare Root CA (Optional but Recommended)
curl -o /etc/ssl/cloudflare/origin-pull-ca.pem \
https://developers.cloudflare.com/ssl/static/authenticated_origin_pull_ca.pem
Verify the Setup
- Open your site in a browser — the padlock icon should appear
- Run SSL Labs Test to check your SSL grade
- In Cloudflare Dashboard → SSL/TLS → Edge Certificates, confirm Universal SSL is active
- Test HTTP redirect:
curl -I http://example.comshould return 301/302
Authenticated Origin Pulls — Extra Security Layer
Cloudflare's "Authenticated Origin Pulls" feature configures your server to only accept HTTPS connections from Cloudflare, preventing attackers who discover your origin IP from bypassing Cloudflare entirely:
# Nginx — verify client certificate from Cloudflare
ssl_client_certificate /etc/ssl/cloudflare/origin-pull-ca.pem;
ssl_verify_client on;
Then enable in Cloudflare Dashboard → SSL/TLS → Origin Server → Authenticated Origin Pulls → Enable.
Frequently Asked Questions
How is Cloudflare Origin Certificate different from Let's Encrypt?
Let's Encrypt is a public CA trusted by all browsers — it works with or without Cloudflare. A Cloudflare Origin Certificate is only trusted by Cloudflare. If you ever remove your domain from Cloudflare, you must replace the Origin Certificate with a publicly trusted one like Let's Encrypt or a paid SSL.
Can I use an Origin Certificate on shared hosting?
It depends on whether your hosting provider supports custom SSL installation. On DirectAdmin-based hosting (like AsiaGB), you can upload a custom certificate via the SSL/TLS Manager in DirectAdmin. Contact your hosting provider to confirm.
What happens when the Origin Certificate expires?
Generate a new certificate in Cloudflare Dashboard and replace the files on your server. To minimize maintenance, select 15-year validity when creating the certificate.
Cloudflare SSL and WordPress: Common Configuration Issues
WordPress sites running behind Cloudflare with an Origin Certificate require a few additional configuration steps that are not always obvious. Skipping these can result in redirect loops, mixed content warnings, or pages that display incorrectly even though the SSL certificate is technically installed correctly.
Set WordPress Site URL to HTTPS
Add these lines to wp-config.php before the require 'wp-settings.php' line to force WordPress to generate HTTPS links throughout the site:
define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');
Fix the Redirect Loop Caused by Flexible SSL Mode
The most common Cloudflare+WordPress redirect loop happens when Cloudflare SSL Mode is set to "Flexible" while WordPress simultaneously enforces HTTPS. The fix is to switch to "Full (Strict)" as described in this guide. Alternatively, if you must use Flexible temporarily, add this to wp-config.php to tell WordPress that incoming requests from Cloudflare are already HTTPS:
// Add before require 'wp-settings.php'
if (isset($_SERVER['HTTP_X_FORWARDED_PROTO'])
&& $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https') {
$_SERVER['HTTPS'] = 'on';
}
Resolve Mixed Content Warnings
After switching your WordPress Site URL to HTTPS, older posts and pages may still contain http:// URLs embedded in their content, causing mixed content warnings in browsers. Use the Better Search Replace plugin or WP-CLI to update all database references at once:
# Replace all HTTP URLs with HTTPS in WordPress database
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' \
--skip-columns=guid --report-changed-only
Monitoring Your SSL Certificate Before It Expires
Even with a 15-year Origin Certificate, it is good practice to set up monitoring for all SSL certificates across your infrastructure. An expired certificate shows a browser error to every visitor immediately with no warning — proactive monitoring prevents this entirely.
| Monitoring Method | Cost | Best For |
|---|---|---|
| Cloudflare Dashboard Alert | Free | Cloudflare Origin Certificates only |
| SSL Labs API | Free | Grade check + expiry date audit |
| openssl CLI via cron | Free | Daily automated check with email alert |
| Uptime monitoring service | Free/Paid | Combined uptime + SSL expiry tracking |
A quick shell one-liner to check the expiration date of your live certificate:
# Check SSL certificate expiry date via openssl
echo | openssl s_client -connect yourdomain.com:443 -servername yourdomain.com 2>/dev/null \
| openssl x509 -noout -dates
Cloudflare Plan Comparison for SSL Features
Origin Certificates are available on every Cloudflare plan including the Free tier. Understanding what each plan includes helps you decide whether to upgrade or stay on the free plan for your security needs.
- Free Plan: Universal SSL, Origin Certificate, Full (Strict) mode, Always Use HTTPS, HSTS, Minimum TLS Version — everything covered in this guide is included at no cost
- Pro Plan ($20/month): Adds Advanced Certificate Manager (ACM), allowing custom TLS certificates and automated certificate renewal management
- Business Plan ($200/month): Adds Custom SSL Upload — you can bring an externally purchased SSL certificate (e.g., a paid Wildcard from DigiCert) and install it directly on Cloudflare's edge
- Enterprise: Dedicated SSL Certificate, custom certificate bundles, multi-level subdomain Wildcard support
Bottom line for most sites: Cloudflare Free Plan + Origin Certificate + Full (Strict) mode delivers enterprise-grade encryption at no additional cost. You only need to upgrade if you require a custom certificate on Cloudflare's edge (Business+) or automated certificate lifecycle management (Pro+).
Security Checklist: Cloudflare Origin Certificate Deployment
Use this checklist to confirm your Cloudflare Origin Certificate deployment is complete and secure:
- Origin Certificate generated in Cloudflare Dashboard and saved to
/etc/ssl/cloudflare/with correct permissions (cert.pem= 644,key.pem= 600) - Web server (Nginx or Apache) configured with certificate paths and reloaded without errors
- Cloudflare SSL Mode set to Full (Strict)
- Always Use HTTPS enabled in Cloudflare Edge Certificates settings
- HSTS enabled with Max Age of at least 6 months
- Authenticated Origin Pulls enabled and
origin-pull-ca.peminstalled (optional but recommended) - Firewall rules restrict Port 443 to Cloudflare IP ranges only (optional for highest security)
- SSL Labs test shows grade A or better
- Browser padlock visible and no mixed content warnings in browser console
Need an SSL Certificate That Works Without Cloudflare?
AsiaGB offers publicly trusted SSL Certificates from RapidSSL, GeoTrust, and DigiCert — DV SSL from 1,000 THB/year, Wildcard SSL from 5,000 THB/year. No Cloudflare required.
View All SSL Certificates