Cloudflare 15-Year Free SSL Certificate: Complete Guide
2026 clarification: the 15-year certificate is an Origin CA certificate, not a browser certificate
Cloudflare Origin CA can issue an origin certificate valid for up to 15 years, but it is for TLS between Cloudflare and the origin only. Browsers and clients that do not traverse Cloudflare do not trust it. Visitors still rely on Cloudflare’s edge certificate for publicly trusted HTTPS. Do not install an Origin CA certificate on a direct public service or switch DNS to DNS-only merely to avoid certificate work.
Use a proxied DNS record, install an Origin CA or publicly trusted certificate at the origin, select Full (strict), and test HTTP-to-HTTPS, the certificate chain, mixed content, and origin firewall access. Restrict private-key access and replace a suspected exposed certificate immediately.
Official references: Cloudflare Origin CA; Full (strict).
The full Origin CA application flow
These steps match the official documentation as of August 2026 (developers.cloudflare.com/ssl/origin-configuration/origin-ca/):
- Open SSL/TLS, Origin Server for the zone in the Cloudflare dashboard and choose Create Certificate.
- Pick a key method: let Cloudflare generate the private key and CSR (RSA or ECC), or paste your own CSR. When Cloudflare generates the key it is shown exactly once, so save it on the spot.
- List the hostnames to cover: the zone apex and first-level wildcard are included by default, and further subdomain wildcards can be added.
- Choose the validity period (up to 15 years), then download in your server format. Apache and Nginx take PEM.
- Install the certificate and key on the origin server, then set the Cloudflare SSL/TLS mode to Full (strict).
Three boundaries where people go wrong
- Long validity does not mean zero maintenance: a 15-year certificate still needs revocation and rebuild if the private key leaks. Put the expiry date in a calendar; revocation lives on the Origin Server page and in the API (the DELETE certificates endpoint).
- Gray-cloud (DNS only) records do not apply: Origin CA only makes sense where traffic flows through the Cloudflare proxy. Subdomains on DNS-only records need a publicly trusted certificate such as Let's Encrypt via certbot.
- API automation: Origin CA certificates have full REST support (create, list, revoke), which suits scripted rotation across many origins. Note that the API authenticates with an Origin CA Key (generated on the Origin Server page), a separate system from ordinary API tokens; mixing them up yields 403.
Nginx and Apache configuration notes
For Nginx, place the PEM certificate and private key where only root or the web service account can read them, point ssl_certificate and ssl_certificate_key at the files, and use the downloaded origin certificate as-is (the Origin CA root is included; no manual chain assembly). Apache uses SSLCertificateFile and SSLCertificateKeyFile the same way. After configuring, verify with openssl s_client directly against the origin (expecting the Origin CA issuer), then confirm no 526 errors through the proxied hostname under Full (strict).
Quick fault reference
- 526 Invalid SSL certificate: Full (strict) rejected the origin certificate. Usually a hostname coverage gap, a self-signed certificate, or files in the wrong order. Re-check coverage on the Origin Server page.
- NET::ERR_CERT_AUTHORITY_INVALID: a browser reached the origin directly (origin IP or gray-cloud host) and saw the Origin CA certificate. That is expected behavior; restore proxying or switch to a public CA certificate.
- Sudden certificate failure: confirm whether the SSL/TLS mode changed or the certificate was rebuilt; a revoked Origin CA certificate is rejected at the edge immediately.