This article helps customers choose the correct Cloudflare SSL/TLS mode and avoid common HTTPS errors.
Overview
For production websites, Libyan Spider recommends installing SSL on the origin first, then using Full (strict) in Cloudflare. Full (strict) validation validates the certificate on the origin server and provides end-to-end HTTPS.
Recommended Steps
- Install a valid SSL certificate on cPanel, Plesk, or the server.
- Verify that
https://yourdomainWorks directly through the hosting configuration, changing Cloudflare settings only when necessary. - In Cloudflare, open SSL/TLS and set the encryption mode to Full (strict).
- Enable Always Use HTTPS only after confirming SSL works.
- Check for mixed-content issues within the website application.
- Avoid Flexible SSL except as a temporary diagnostic state.
Common Mistakes to Avoid
- Using Flexible SSL while the origin redirects HTTP to HTTPS, which can cause redirect loops.
- Using Full instead of Full (strict) when a valid origin certificate is available.
- Forgetting to renew or reinstall the origin certificate.
- Assuming Cloudflare edge SSL replaces the SSL certificate needed on the server.