SSL
ssl
Analyze
ssl.analyze
Methods
Returns the set of hostnames, the signature algorithm, and the expiration date of the certificate.
Certificate Packs
ssl.certificate_packs
Methods
For a given zone, order an advanced certificate pack.
For a given zone, delete an advanced certificate pack.
For a given zone, restart validation or add cloudflare branding for an advanced certificate pack. The former is only a validation operation for a Certificate Pack in a validation_timed_out status.
For a given zone, get a certificate pack.
For a given zone, list all active certificate packs.
Domain types
The number of days for which the certificate should be valid.
Status of certificate pack.
Validation method in use for a certificate pack order.
ssl.certificate_packs.quota
Methods
For a given zone, list certificate pack quotas.
Recommendations
ssl.recommendations
Methods
Retrieve the SSL/TLS Recommender's recommendation for a zone.
Universal
ssl.universal
Methods
Patch Universal SSL Settings for a Zone.
The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.
Example: X-Auth-Email: user@example.com
The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.
Example: X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194
SSL and Certificates Write
Identifier
Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates from being ordered. If there are no advanced certificates or custom certificates uploaded for the domain, visitors will be unable to access the domain over HTTPS.
By disabling Universal SSL, you understand that the following Cloudflare settings and preferences will result in visitors being unable to visit your domain unless you have uploaded a custom certificate or purchased an advanced certificate.
- HSTS
- Always Use HTTPS
- Opportunistic Encryption
- Onion Routing
- Any Page Rules redirecting traffic to HTTPS
Similarly, any HTTP redirect to HTTPS at the origin while the Cloudflare proxy is enabled will result in users being unable to visit your site without a valid certificate at Cloudflare's edge.
If you do not have a valid custom or advanced certificate at Cloudflare's edge and are unsure if any of the above Cloudflare settings are enabled, or if any HTTP redirects exist at your origin, we advise leaving Universal SSL enabled for your domain.
Whether the API call was successful
Get Universal SSL Settings for a Zone.
Domain types
Verification
ssl.verification
Methods
Edit SSL validation method for a certificate pack. A PATCH request will request an immediate validation check on any certificate, and return the updated status. If a validation method is provided, the validation will be immediately attempted using that method.
Get SSL Verification Info for a Zone.
Domain types