Free SSL cert questions

I installed free ssl certificate on my website,, from cloudflare some days ago, and it was successful but the SSL/TLS Status is still having problems on my cpanel.

Please check the attachments :point_down::point_down::point_down::point_down:: for better understanding:

Please help solve these issues


Given from cPanel AutoSSL, or Cloudflare Origin CA certificate, or some other? :thinking:

If you’ve used and generated a Cloudflare Origin CA certificate, it would always show some alert in cPanel interface since it’s self-signed one which works only for HTTP(S) traffic while using Cloudflare proxy :orange: . Meaning, your e-mail related services wouldn’t function and work at all. cPanel wouldn’t be able to renew it neither. To get rid of cPanel AutoSSL notifications, uncheck it from renewing process.

Otherwise, stick to the cPanel AutoSSL, use Full SSL (not strict), and make sure to allow both HTTP and HTTPS traffic so cPanel AutoSSL can renew it. Nevertheless, allowing HTTP traffic IMHO isn’t the best practice nowadays.

I’d rather keep it secured & safe, including the Full SSL (Strict).

There are posts around some workaround(s) here about this topic too. Sharing below, hope it helps. In the meantime, feel free to write back.

From the shared screenshot above, you also have deep-subdomain issue like the which can be fixed by using the Advanced Certificate Manager:



  1. My domain and subdomain is showing not :no_entry_sign: secured :unlock::unlock::unlock: on Android but is secured :lock: on desktop.,, Please check attachments for better understanding :point_down::point_down::point_down::point_down::point_down::point_down:

  2. Domain SSL/TLS STATUS is showing this and I don’t understand :point_down::point_down:

The certificate has the For following errors: Certificate #2 (ST=California,L=San

Francisco,OU=Cloudflare Origin

SSL Certificate

Gene Authority,O=Cloudflare, Inc.,C=US) has 2 validation Current User errors:


Please help me for solutions :pray::pray::pray::pray:


The Untrusted notification is to be expected when you make a direct connection to a hostname that uses a Cloudflare Origin CA certificate. Cloudflare Origin CA certificates are not trusted by web browsers and are used to secure the connection between the origin server and the Cloudflare proxy. When you use a Cloudflare Origin CA certificate with a record that is :orange: Proxied, you will not see the Untrusted notification because Cloudflare trusts that certificate.

Set the :grey: to :orange: and it should fix that.


Mr, I have spent almost 5 days on cloudflare community, my problem not solved, I have message before and you replied:
Please do not open duplicate topics. It dilutes resources and makes it take longer for you and others to receive assistance.

Duplicate of Free SSL cert questions

Please :pray: how can I get my problem solved. I’m having 4 issues with my domain since I changed my namesavers to cloudflare, I have scroll almost all the topics but still can’t fix my problem please can you help solve my issues,

@tonyokolie51 have you followed the advice given in the most recent reply by on your thread

Set the :grey: to :orange: and it should fix that. Please can you use examples where to do this because I don’t understand

And my domain on mobile :calling: showing not secured​:unlock:
But on desktop :desktop_computer: is secured​:lock:
Please how can I fix this

Rather than replying on another thread @tonyokolie51, please continue the discussion here.

From what I can see the domain is proxied

$ dig		300	IN	A		300	IN	A

The site also loads with SSL for me on both mobile and desktop.

Have you tried accessing the site on a different device to rule out the possibility of an issue with the device you are using?

Thank you so much for this, you are good
It loads in another device.
So how will I fix this on my device?

Because I have clear all my cache like more than 30 times But still the same issues since 5 days now

@tonyokolie51, you should also make sure your encryption mode is Full Strict, otherwise none of the certificates will be validated and the site will still be insecure. As @fritex already wrote.

Yes I did that 2 days ago

This is outside of my scope of knowledge unfortunately.

This is my DNS records
Please help me check if there is mistake from here.

They all appear correct.

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.