Why does Cloudflare automatically switch SSL to “Full Strict” causing errors

What is the name of the domain?

liderkocdanismanlik

What is the error number?

Error code 526

What is the issue you’re encountering

Invalid SSL certificate

What are the steps to reproduce the issue?

I am managing a Cloudflare account with hundreds of sites, and I am encountering a recurring issue with SSL settings. Specifically, for reasons unknown, some of my sites’ SSL/TLS encryption mode gets automatically switched to “Full Strict”, which leads to the error: “Invalid SSL certificate Error code 526.”

Key Details:
1. I am not manually changing the SSL setting: The switch to “Full Strict” happens automatically. I don’t have any page rules or API integrations that I’m aware of that would cause this behavior.
2. Manually switching back to “Full” fixes the issue immediately. However, managing this manually for hundreds of sites is not practical.
3. Why is Cloudflare doing this? I don’t understand why Cloudflare would automatically change the SSL mode to “Full Strict” without my intervention.
4. How can I fix this permanently? Is there a way to:
• Prevent Cloudflare from automatically switching the SSL mode to “Full Strict”?
• Set all sites’ SSL mode to “Full” in bulk and ensure they stay that way?

I’ve already checked:
• Edge Certificates: Nothing seems out of the ordinary, but I am not sure if automatic certificate renewals are triggering this.
• Page Rules: None are affecting the SSL settings.

If anyone has encountered a similar issue or has insight into why this is happening and how to address it, I’d appreciate your guidance. Additionally, if there is a way to bulk-change the SSL mode for all sites via the API or other means, that would be immensely helpful.

Thank you in advance for your help!

Review your audit log to determine when / how the change is being made. Cloudflare isn’t changing your SSL settings.

You really should set valid certificates on your origin if at all possible.

Thank you for your response. However, I received an email from Cloudflare confirming that they are indeed automatically changing the SSL/TLS encryption mode for some of my zones. Here’s the content of the email I received

Content:

“We have automatically upgraded the SSL/TLS encryption mode for the following zone(s):

Additional information on all SSL/TLS options can be found at Origin Server Configuration - Encryption modes. You are receiving these emails because Automatic SSL/TLS Upgrader is enabled for one or more of your domains. To disable, please disable Automatic SSL/TLS Upgrader in the dashboard.

Thanks,

The Cloudflare Team”

1 Like

Go here to do that, https://dash.cloudflare.com/?to=/:account/:zone/ssl-tls/configuration. Select Custom and not automatic. Reference, Introducing Automatic SSL/TLS: securing and simplifying origin connectivity

2 Likes

Thank you for the detailed response and the reference link. I will review this setting in the dashboard and explore the configuration further.

1 Like

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.