Free HTTPS for Your Website: Cloudflare Origin Certificate + Nginx (Full Strict)

⏱ 2 min readUpdated 28 September 2026

With Cloudflare proxying your domain, visitors connect to Cloudflare over HTTPS — but the link from Cloudflare to your server must be encrypted too. An Origin Certificate is free, valid for up to 15 years and trusted by Cloudflare.

In this article
  1. 1. Create the certificate
  2. 2. Install on the server
  3. 3. Nginx server block
  4. 4. Cloudflare settings
  5. Troubleshooting

1. Create the certificate

Cloudflare dashboard → your domain → SSL/TLS → Origin Server → Create Certificate. Keep the default RSA key, hostnames example.com and *.example.com, validity 15 years. Copy the certificate and the private key (the key is shown only once).

2. Install on the server

sudo mkdir -p /etc/ssl/cloudflare
sudo nano /etc/ssl/cloudflare/example.com.pem   # paste the certificate
sudo nano /etc/ssl/cloudflare/example.com.key   # paste the private key
sudo chmod 600 /etc/ssl/cloudflare/example.com.key

3. Nginx server block

server {
    listen 443 ssl;  listen [::]:443 ssl;
    server_name example.com www.example.com;
    ssl_certificate     /etc/ssl/cloudflare/example.com.pem;
    ssl_certificate_key /etc/ssl/cloudflare/example.com.key;
    add_header Strict-Transport-Security "max-age=31536000" always;
    root /var/www/example.com;
    # ... your site config ...
}
server { listen 80; listen [::]:80; server_name example.com www.example.com; return 301 https://$host$request_uri; }
sudo nginx -t && sudo systemctl reload nginx

4. Cloudflare settings

  • SSL/TLS mode: Full (strict).
  • Edge Certificates: Always Use HTTPS on, minimum TLS 1.2, TLS 1.3 on.
  • DNS records for @ and www: Proxied (orange cloud).

Troubleshooting

Error Cause
525 SSL handshake failed Nginx isn’t serving HTTPS for that hostname — wrong server_name, or no 443 block.
526 Invalid SSL certificate Full (strict) with a self-signed or expired certificate — install the Origin Certificate.
Too many redirects SSL mode set to Flexible while the server also redirects to HTTPS — use Full (strict).
⚠️ Origin certificates are trusted only by Cloudflare. If you turn the orange cloud off (DNS only), browsers will show a certificate warning.

Full setup from scratch: free Oracle Cloud server + one setup script.

✨ Ask AI about this article

Stuck on a step? Ask a question and the AI answers using this article.

Free · AI can be wrong