Cipher suites | Cloudflare SSL/TLS docs (2024)

Cipher suites are a combination of ciphers used to negotiate security settings during the SSL/TLS handshake (and therefore separate from the SSL/TLS protocol).


This section covers cipher suites used in connections between clients — such as your visitor’s browser — and the Cloudflare network. For information about cipher suites used between Cloudflare and your origin server, refer to Origin server > Cipher suites.

Cipher suites and edge certificates

While the cipher suitesused by default for all Cloudflare domains/zones are meant tobalance security and compatibility, some of them might be considered weakby third-party testing tools, such as the Qualys SSL Labs test.

If the default option (Legacy) does not meet your business requirements, you can purchase the Advanced Certificate Manager add-on to be able to specify more secure cipher suites.

Custom cipher suites is a hostname-level setting. Once specified, the configuration is applicable to all edge certificates used to connect to the hostname(s), regardless of certificate type (universal, advanced, or custom).

Although configured independently, cipher suites interact with other SSL/TLS settings.

Minimum TLS Version

You can specify a minimum TLS version that is required for a client to connect to your website or application.

For example, if TLS 1.1 is selected as the minimum, visitors attempting to connect using TLS 1.0 will be rejected while visitors attempting to connect using TLS 1.1, 1.2, or 1.3 (if enabled) will be allowed.

Each cipher suite relates to a specific minimum protocol that it supports. This means that if you use a higher security level for your cipher suites and stop supporting TLS 1.0, you should also adjust your minimum TLS version accordingly.

Compliance standards can also require you to up the minimum TLS version accepted in connections to your website or application.

TLS 1.3

You cannot set specific TLS 1.3 ciphers. Instead, you can enable TLS 1.3 for your entire zone and Cloudflare will use all applicable TLS 1.3 cipher suites.

In combination with this, you can still disable weak cipher suites for TLS 1.0-1.2.

Resources

Limitations

It is not possible to configure cipher suites for Cloudflare Pages hostnames.

Cipher suites | Cloudflare SSL/TLS docs (2024)
Top Articles
Key differences Between TLS 1.2 and TLS 1.3 | Glossary | A10 Networks
How to enable Transport Layer Security (TLS) 1.2 on clients - Configuration Manager
Chs.mywork
Pet For Sale Craigslist
Uca Cheerleading Nationals 2023
Cintas Pay Bill
Fat Hog Prices Today
Recent Obituaries Patriot Ledger
Deshret's Spirit
Gina's Pizza Port Charlotte Fl
Power Outage Map Albany Ny
Hillside Funeral Home Washington Nc Obituaries
Slushy Beer Strain
Oc Craiglsit
Marion County Wv Tax Maps
Studentvue Columbia Heights
Q33 Bus Schedule Pdf
How do I get into solitude sewers Restoring Order? - Gamers Wiki
O'Reilly Auto Parts - Mathis, TX - Nextdoor
Ac-15 Gungeon
South Bend Weather Underground
Netwerk van %naam%, analyse van %nb_relaties% relaties
Belledelphine Telegram
Dr. Nicole Arcy Dvm Married To Husband
Safeway Aciu
O'reilly's In Monroe Georgia
Pdx Weather Noaa
Craigslist Texas Killeen
Western Gold Gateway
Top-ranked Wisconsin beats Marquette in front of record volleyball crowd at Fiserv Forum. What we learned.
The Thing About ‘Dateline’
Www Craigslist Com Brooklyn
Deshuesadero El Pulpo
Mixer grinder buying guide: Everything you need to know before choosing between a traditional and bullet mixer grinder
2700 Yen To Usd
Craigslist Putnam Valley Ny
Suffix With Pent Crossword Clue
Skyward Marshfield
The Realreal Temporary Closure
Torrid Rn Number Lookup
Charli D'amelio Bj
Login
Egg Inc Wiki
St Als Elm Clinic
Nfl Espn Expert Picks 2023
BYU Football: Instant Observations From Blowout Win At Wyoming
Who We Are at Curt Landry Ministries
All Obituaries | Roberts Funeral Home | Logan OH funeral home and cremation
Craigslist Farm And Garden Missoula
Latest Posts
Article information

Author: Aron Pacocha

Last Updated:

Views: 5454

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Aron Pacocha

Birthday: 1999-08-12

Address: 3808 Moen Corner, Gorczanyport, FL 67364-2074

Phone: +393457723392

Job: Retail Consultant

Hobby: Jewelry making, Cooking, Gaming, Reading, Juggling, Cabaret, Origami

Introduction: My name is Aron Pacocha, I am a happy, tasty, innocent, proud, talented, courageous, magnificent person who loves writing and wants to share my knowledge and understanding with you.