If Cloudflare is providing authoritative DNS for your domain, Cloudflare will issue a backup Universal SSL certificate for every standard Universal certificate issued.
Backup certificates are wrapped with a different private key and issued from a different Certificate Authority — either Google Trust Services, Let's Encrypt, Sectigo, or SSL.com — than your domain's primary Universal SSL certificate.
These backup certificates are not normally deployed, but they will be deployed automatically by Cloudflare in the event of a certificate revocation or key compromise.
For additional details, refer to the introductory blog post ↗.
| Free | Pro | Business | Enterprise | |
|---|---|---|---|---|
| Availability | Yes | Yes | Yes | Yes |
| Can opt out? | No | No | No | Yes |
Enterprise customers can request to opt out of backup certificates by opening a support case. Opting out removes the backup-certificate redundancy for your domain.
After you turn off and quickly turn Universal SSL back on, your domain may end up without a backup certificate.
When Universal SSL is toggled off and on in quick succession, certificate processing jobs are not guaranteed to run in the order they were submitted. This race condition can cause a newly issued backup certificate to be deleted before it becomes active.
To recover your backup certificate:
- Turn Universal SSL off again.
- Wait several minutes.
- Turn Universal SSL back on, then allow time for Cloudflare to issue a new backup certificate.
If you need uninterrupted certificate coverage, consider ordering an Advanced Certificate Manager certificate before toggling Universal SSL.
For more troubleshooting help, refer to Troubleshooting SSL errors.