Blogs›Cloudflare›HTTPS Adoption & Security Indicators
HTTPS Adoption & Security Indicators
Cloudflare has been offering full IPv6 support and an IPv6-to-IPv4 gateway since 2012, making it easy for customers to transition to IPv6. This includes features like IPv6 Compatibility enablement in the dashboard and Pseudo IPv4 for legacy IPv4 applications. The company actively supports emerging networking technologies and provides guidance for developers navigating IPv6-only environments, such as those mandated by Apple for iOS apps. This support aims to simplify the complex global transition. Universal SSL has been rolled out to all customers, including free tier users, doubling the number of SSL-enabled sites. This is achieved by automatically provisioning SSL certificates on Cloudflare's network, supporting both root domains and wildcard subdomains. For sites without prior SSL, Flexible SSL mode is enabled by default, encrypting traffic between browsers and Cloudflare. Full or Strict SSL modes are recommended for end-to-end encryption. The challenges of CPU load and IPv4 exhaustion were addressed by leveraging ECDSA cipher suites and Server Name Indication (SNI) for modern browsers, allowing multiple customer sites to share the same IP address. Legacy browsers, such as Internet Explorer on Windows XP and pre-Ice Cream Sandwich Android, are not supported on the free plan. Paid plans continue to support all browsers. Universal SSL also enables broader support for the SPDY protocol. Future plans include leveraging IPv6 connections for SNI-less browsers and encouraging users to upgrade to modern browsers and operating systems. A 'Better Browser' app is available to prompt users to upgrade. The decision to offer Universal SSL to all customers, even at a potential short-term revenue cost, aligns with Cloudflare's mission to build a better, encrypted internet. The rollout is ongoing, with full provisioning expected within 24 hours for most customers. Support for hosting partners will be enabled later.