Skip to content

SYSTEM Cited by 1 source

Cloudflare Automatic SSL/TLS

What

Automatic SSL/TLS (building in public since 2024) is the Cloudflare product that automatically secures and simplifies the Cloudflare → origin connection. Because Cloudflare is a reverse proxy, what looks like one secure connection is two independent TLS connections — visitor↔Cloudflare and Cloudflare↔origin — each with its own handshake, identity checks, and keys. Automatic SSL/TLS manages the second one: it scans each origin to determine the safest encryption mode and configuration, and upgrades origin connections without customer action, reverting automatically if an upgrade misbehaves. (Source: sources/2026-09-08-cloudflare-automatic-key-exchange-faster-post-quantum-secure-origin-han)

It is the sibling of Universal SSL (2014), which did the same default-on job for the visitor→Cloudflare hop — together forming Cloudflare's "encryption by default, no extra cost, no configuration" posture (see patterns/default-on-security-upgrade).

The scanning pipeline

The durable systems-design contribution is an origin-scanning pipeline that probes origins out-of-band (off the production traffic path) to learn their capabilities, then uses monitored progressive rollout with automatic rollback to apply upgrades safely across millions of origins with no advance knowledge of each one's configuration. This same pipeline is reused by Automatic Key Exchange (2026) to learn per-origin key-agreement support and lead with the strongest group. The rollback discipline is shared: an encryption-mode upgrade (Automatic SSL/TLS) or a key-agreement preference (Automatic Key Exchange) that raises failures/HRRs above baseline is reverted.

Extensions

  • Automatic Key Exchange (2026-09-08) — per-origin TLS 1.3 key-agreement selection preferring post-quantum X25519MLKEM768, built on the same scanning pipeline.

Seen in

Last updated · 766 distilled / 2,225 read