DNS, Security & Integrations
Configure Cloudflare Full (Strict) SSL
Set Cloudflare's SSL mode to Full (Strict) properly, closing the gap that weaker SSL modes leave open.
The Problem
Your site uses Cloudflare, but the SSL mode is set to something less secure than Full (Strict) — or switching to Strict mode breaks the site with a redirect loop or error because the origin server certificate isn't valid yet.
About this problem
Cloudflare offers several SSL modes between your visitors and your origin server: Off, Flexible, Full, and Full (Strict). Flexible only encrypts the visitor-to-Cloudflare leg, leaving the Cloudflare-to-origin leg in plain HTTP — which looks secure to visitors but isn't actually end-to-end encrypted, and often causes redirect loops. Full (Strict) is the properly secure option, requiring a valid, trusted SSL certificate on your actual origin server, not just at Cloudflare's edge.
Many sites get stuck on Flexible mode because it "just works" without needing an origin certificate, without realising it's the weaker option — switching to Strict properly requires the origin server to have its own valid certificate first.
What's Included
- Checking the origin server has a valid SSL certificate installed (installing one first if it doesn't)
- Switching Cloudflare's SSL mode to Full (Strict)
- Fixing any resulting redirect loop or mixed-content issue that the mode change exposes
- Verifying the site loads correctly, end-to-end encrypted, after the change
What's NOT Included
- Installing an origin certificate if that's a separate, larger task (handled as part of this service if needed, just scoped accordingly)
- Cloudflare account/plan billing issues
- DNS configuration unrelated to the SSL mode itself
How It Works
- Check the current Cloudflare SSL mode and confirm whether the origin server already has a valid SSL certificate.
- If the origin doesn't have a valid certificate yet, install one (a Cloudflare Origin CA certificate is a common, free option for this specific purpose).
- Switch the Cloudflare SSL mode to Full (Strict).
- Check for and resolve any redirect loop this change might expose, which usually means the server's own redirect rules need adjusting to match.
- Verify the full chain — visitor to Cloudflare, and Cloudflare to origin — is genuinely encrypted and loading without errors.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- What's the difference between Cloudflare's SSL modes?
- Flexible only encrypts between visitors and Cloudflare, leaving the connection to your actual server unencrypted; Full checks for any certificate at the origin; Full (Strict) requires a valid, trusted certificate at the origin for genuine end-to-end encryption.
- Why does my site show a redirect loop after switching to Full (Strict)?
- This usually means your origin server is still redirecting based on assumptions that don't match Strict mode's requirements, or the origin certificate isn't valid yet — both get checked and fixed together.
- Do I need to buy a certificate for my origin server to use Full (Strict)?
- Not necessarily — Cloudflare offers free Origin CA certificates specifically designed for this purpose, which are trusted by Cloudflare even though they're not publicly trusted certificates.
- Is Flexible SSL mode actually insecure?
- It's not fully end-to-end encrypted, which matters more for sensitive data (logins, payments) — it "looks" secure to visitors but leaves a real gap between Cloudflare and your server.
- Will switching SSL modes affect my SEO?
- Not directly, though a broken site from a badly handled switch certainly would — that's exactly why the switch is tested and verified rather than just flipped and left.
- Can I switch back to Flexible if Full (Strict) causes problems?
- Yes, though the better approach is fixing the actual origin certificate issue so Full (Strict) works properly, since that's the genuinely secure configuration.