SYSTEM Cited by 1 source
Cloudflare Automatic SSL/TLS¶
What¶
Automatic SSL/TLS (building in public since 2024) is the Cloudflare product that automatically secures and simplifies the Cloudflare → origin connection. Because Cloudflare is a reverse proxy, what looks like one secure connection is two independent TLS connections — visitor↔Cloudflare and Cloudflare↔origin — each with its own handshake, identity checks, and keys. Automatic SSL/TLS manages the second one: it scans each origin to determine the safest encryption mode and configuration, and upgrades origin connections without customer action, reverting automatically if an upgrade misbehaves. (Source: sources/2026-09-08-cloudflare-automatic-key-exchange-faster-post-quantum-secure-origin-han)
It is the sibling of Universal SSL (2014), which did the same default-on job for the visitor→Cloudflare hop — together forming Cloudflare's "encryption by default, no extra cost, no configuration" posture (see patterns/default-on-security-upgrade).
The scanning pipeline¶
The durable systems-design contribution is an origin-scanning pipeline that probes origins out-of-band (off the production traffic path) to learn their capabilities, then uses monitored progressive rollout with automatic rollback to apply upgrades safely across millions of origins with no advance knowledge of each one's configuration. This same pipeline is reused by Automatic Key Exchange (2026) to learn per-origin key-agreement support and lead with the strongest group. The rollback discipline is shared: an encryption-mode upgrade (Automatic SSL/TLS) or a key-agreement preference (Automatic Key Exchange) that raises failures/HRRs above baseline is reverted.
Extensions¶
- Automatic Key Exchange (2026-09-08) — per-origin TLS 1.3 key-agreement selection preferring post-quantum X25519MLKEM768, built on the same scanning pipeline.
Seen in¶
- sources/2026-09-08-cloudflare-automatic-key-exchange-faster-post-quantum-secure-origin-han — described as the parent product whose origin-scanning pipeline Automatic Key Exchange reuses, and whose encryption-mode revert behavior is the model for key-agreement rollback. "In public since 2024."
Related¶
- systems/cloudflare-automatic-key-exchange — the 2026 key-agreement extension.
- systems/cloudflare-universal-ssl — the visitor-side default-on sibling.
- measure-dont-guess-via-active-probing — the scanning-pipeline pattern.
- patterns/default-on-security-upgrade — the posture it embodies.
- patterns/staged-rollout — the rollout+rollback discipline.
- companies/cloudflare — the operator.