Skip to content
Cloudflare's Internet facing SSL configuration
Branch: master
Clone or download

Latest commit

Latest commit 33dbff6 Oct 18, 2019


Type Name Latest commit message Commit time
Failed to load latest commit information.
patches Merge pull request #66 from Injust/master Jun 28, 2017
.gitignore Update README and .gitignore May 3, 2014
LICENSE Initial commit May 3, 2014 Don't mention OpenSSL Jun 6, 2017
conf Remove P-224 Oct 18, 2019


Cloudflare's Internet facing SSL cipher configuration

This repository tracks the history of the SSL cipher configuration used for Cloudflare's public-facing SSL web servers. The repository tracks an internal Cloudflare repository, but dates may not exactly match when changes are made.

There is a single file called conf which contains the configuration used in Cloudflare's NGINX servers. This is only a fragment of the configuration.

ChaCha20/Poly1305 patch

Cloudflare uses a patch for OpenSSL that enables the ChaCha20/Poly1305 cipher suites and implements special logic to ensure it is only taken if it is the client's top cipher choice. Without this patch, the cipher suite choice in the configuration will not work correctly.

You can’t perform that action at this time.