How to Install Cloudflare Origin Certificate on VPS and Hosting

What Is a Cloudflare Origin Certificate?

A Cloudflare Origin Certificate is a free SSL certificate issued by Cloudflare specifically for securing the connection between Cloudflare's edge network and your origin server. Unlike certificates from public CAs like Let's Encrypt, a Cloudflare Origin Certificate is only trusted by Cloudflare — if users connect directly to your server bypassing Cloudflare, browsers will display a "certificate not trusted" warning.

When used correctly behind Cloudflare with SSL Mode set to "Full (Strict)", an Origin Certificate secures both legs of the connection: visitor → Cloudflare (via Cloudflare's Universal SSL) and Cloudflare → your server (via the Origin Certificate). This is the recommended configuration for maximum security.

Understanding Cloudflare SSL Modes

Before installing an Origin Certificate, understand the four Cloudflare SSL modes:

Goal: Enable SSL Mode "Full (Strict)" on Cloudflare, then install the Origin Certificate on your server. Follow the steps below to achieve this configuration.

Step 1 — Generate a Cloudflare Origin Certificate

In Cloudflare Dashboard, navigate to SSL/TLS → Origin Server:

  1. Click "Create Certificate"
  2. Choose "Generate private key and CSR with Cloudflare" (simplest) or "Use my own private key and CSR"
  3. Specify hostnames — e.g., example.com and *.example.com
  4. Select certificate validity (15 years recommended for origins since renewal requires reinstallation)
  5. Click "Create"

Cloudflare generates the Origin Certificate and Private Key. Save both files immediately — the Private Key will not be shown again.

Step 2 — Save Certificate Files on Your Server

mkdir -p /etc/ssl/cloudflare
nano /etc/ssl/cloudflare/cert.pem    # paste Origin Certificate
nano /etc/ssl/cloudflare/key.pem     # paste Private Key

chmod 644 /etc/ssl/cloudflare/cert.pem
chmod 600 /etc/ssl/cloudflare/key.pem

Step 3A — Install on Nginx

server {
    listen 443 ssl http2;
    server_name example.com;

    ssl_certificate     /etc/ssl/cloudflare/cert.pem;
    ssl_certificate_key /etc/ssl/cloudflare/key.pem;

    ssl_protocols       TLSv1.2 TLSv1.3;
    ssl_ciphers         HIGH:!aNULL:!MD5;

    # ... your site configuration ...
}

server {
    listen 80;
    server_name example.com;
    return 301 https://$host$request_uri;
}
nginx -t && systemctl reload nginx

Step 3B — Install on Apache

<VirtualHost *:443>
    ServerName example.com
    SSLEngine on
    SSLCertificateFile    /etc/ssl/cloudflare/cert.pem
    SSLCertificateKeyFile /etc/ssl/cloudflare/key.pem

    SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
    SSLCipherSuite HIGH:!aNULL:!MD5

    # ... DocumentRoot and other directives ...
</VirtualHost>
apachectl configtest && systemctl reload apache2

Step 4 — Set SSL Mode to Full (Strict) on Cloudflare

Return to Cloudflare Dashboard → SSL/TLS → Overview and select "Full (Strict)". This is the most critical step — without it, Cloudflare may still connect to your origin over HTTP regardless of your certificate installation.

Warning: Before switching to Full (Strict), confirm the Origin Certificate is correctly installed on your server. Switching to this mode without a valid server certificate will immediately break your site.

Step 5 — Download Cloudflare Root CA (Optional but Recommended)

curl -o /etc/ssl/cloudflare/origin-pull-ca.pem \
  https://developers.cloudflare.com/ssl/static/authenticated_origin_pull_ca.pem

Verify the Setup

Authenticated Origin Pulls — Extra Security Layer

Cloudflare's "Authenticated Origin Pulls" feature configures your server to only accept HTTPS connections from Cloudflare, preventing attackers who discover your origin IP from bypassing Cloudflare entirely:

# Nginx — verify client certificate from Cloudflare
ssl_client_certificate /etc/ssl/cloudflare/origin-pull-ca.pem;
ssl_verify_client on;

Then enable in Cloudflare Dashboard → SSL/TLS → Origin Server → Authenticated Origin Pulls → Enable.

Frequently Asked Questions

How is Cloudflare Origin Certificate different from Let's Encrypt?

Let's Encrypt is a public CA trusted by all browsers — it works with or without Cloudflare. A Cloudflare Origin Certificate is only trusted by Cloudflare. If you ever remove your domain from Cloudflare, you must replace the Origin Certificate with a publicly trusted one like Let's Encrypt or a paid SSL.

Can I use an Origin Certificate on shared hosting?

It depends on whether your hosting provider supports custom SSL installation. On DirectAdmin-based hosting (like AsiaGB), you can upload a custom certificate via the SSL/TLS Manager in DirectAdmin. Contact your hosting provider to confirm.

What happens when the Origin Certificate expires?

Generate a new certificate in Cloudflare Dashboard and replace the files on your server. To minimize maintenance, select 15-year validity when creating the certificate.

Cloudflare SSL and WordPress: Common Configuration Issues

WordPress sites running behind Cloudflare with an Origin Certificate require a few additional configuration steps that are not always obvious. Skipping these can result in redirect loops, mixed content warnings, or pages that display incorrectly even though the SSL certificate is technically installed correctly.

Set WordPress Site URL to HTTPS

Add these lines to wp-config.php before the require 'wp-settings.php' line to force WordPress to generate HTTPS links throughout the site:

define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');

Fix the Redirect Loop Caused by Flexible SSL Mode

The most common Cloudflare+WordPress redirect loop happens when Cloudflare SSL Mode is set to "Flexible" while WordPress simultaneously enforces HTTPS. The fix is to switch to "Full (Strict)" as described in this guide. Alternatively, if you must use Flexible temporarily, add this to wp-config.php to tell WordPress that incoming requests from Cloudflare are already HTTPS:

// Add before require 'wp-settings.php'
if (isset($_SERVER['HTTP_X_FORWARDED_PROTO'])
    && $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https') {
    $_SERVER['HTTPS'] = 'on';
}

Resolve Mixed Content Warnings

After switching your WordPress Site URL to HTTPS, older posts and pages may still contain http:// URLs embedded in their content, causing mixed content warnings in browsers. Use the Better Search Replace plugin or WP-CLI to update all database references at once:

# Replace all HTTP URLs with HTTPS in WordPress database
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' \
  --skip-columns=guid --report-changed-only

Monitoring Your SSL Certificate Before It Expires

Even with a 15-year Origin Certificate, it is good practice to set up monitoring for all SSL certificates across your infrastructure. An expired certificate shows a browser error to every visitor immediately with no warning — proactive monitoring prevents this entirely.

Monitoring MethodCostBest For
Cloudflare Dashboard AlertFreeCloudflare Origin Certificates only
SSL Labs APIFreeGrade check + expiry date audit
openssl CLI via cronFreeDaily automated check with email alert
Uptime monitoring serviceFree/PaidCombined uptime + SSL expiry tracking

A quick shell one-liner to check the expiration date of your live certificate:

# Check SSL certificate expiry date via openssl
echo | openssl s_client -connect yourdomain.com:443 -servername yourdomain.com 2>/dev/null \
  | openssl x509 -noout -dates

Cloudflare Plan Comparison for SSL Features

Origin Certificates are available on every Cloudflare plan including the Free tier. Understanding what each plan includes helps you decide whether to upgrade or stay on the free plan for your security needs.

Bottom line for most sites: Cloudflare Free Plan + Origin Certificate + Full (Strict) mode delivers enterprise-grade encryption at no additional cost. You only need to upgrade if you require a custom certificate on Cloudflare's edge (Business+) or automated certificate lifecycle management (Pro+).

Security Checklist: Cloudflare Origin Certificate Deployment

Use this checklist to confirm your Cloudflare Origin Certificate deployment is complete and secure:

Need an SSL Certificate That Works Without Cloudflare?

AsiaGB offers publicly trusted SSL Certificates from RapidSSL, GeoTrust, and DigiCert — DV SSL from 1,000 THB/year, Wildcard SSL from 5,000 THB/year. No Cloudflare required.

View All SSL Certificates