Error 525 - need clarification

I added a new site to CloudFlare and am getting a 525 error. The URL is From what I understand even though I am using CF’s Full SSL/TLS encryption mode I still need to install a NON self signed ssl certificate on my server as well? Is this correct? And if correct then why would I use CF’s cert if I still need to get my own?

With Full you need a certificate, but it is not validated so can be self signed, expired etc. Full strict requires a certificate that is valid (either issued by a trusted CA or a Cloudflare Origin Certificate. From the documentation:

Full SSL: Your origin supports HTTPS, but the certificate installed does not match your domain or is self-signed. Cloudflare will connect to your origin over HTTPS, but will not validate the certificate.

Full (strict): Your origin has a valid certificate (not expired and signed by a trusted CA or Cloudflare Origin CA) installed. Cloudflare will connect over HTTPS and verify the cert on each request.

You need to verify the configuration on your origin as 525 generally means your SSL configuration is not valid.

Using a valid certificate in a Full Strict configuration provides the greatest level of security end-to-end, and is the recommended configuration.

Thank you for your reply.

Our installed SSL is self-signed so it should work. The origin supports SSL, installed SSL is self-signed and TLS 1.2 is the default.

But the connection is still failing. Perhaps the problem is with CloudFlare?

To illustrate TLS 1.2 and the SSL is self-signed on the origin server.

Hello all. Can anyone offer some input on this matter?

Strange since 5buckstraffic… is running (and working) behind Cloudflare. The only difference i can spot is that 5buckstraffic… has a valid DV certificate.

Are you sure that your (vHost) configuration is correct?

The problem has been resolved. It seems when the CloudFlare account was created the A record IP was no auto populated correctly. Upon updating the IP it works now. Thank you for your help.

Your site will be still insecure as long as you do not have a proper certificate in place.

What do you mean? I have a self signed certificate as CloudFlare instructs for Full encryption mode. Why will my site not be secure?

“Full” is only very partially secure. Only “Full strict” is secure and cannot be intercepted (at least not without compromising a CA).

On “Full” Cloudflare is not verifying the certificate (which it obviously cannot do with a self-signed certificate) and hence everyone who can intercept the connection can place their own certificate.

Switch to “Full strict” and configure a proper certificate if you want a secure site.

I see. Ok thank you for explaining. Have a good day.

