Website Security & Threat Management
Introducing Strict SSL: Protecting Against a On-Path Attack on Origin Traffic

Introducing Strict SSL: Protecting Against a On-Path Attack on Origin Traffic

2/14/2014 · Nick Sullivan

What this post added

Introduced 'Full SSL (Strict)' mode, which adds origin server certificate validation to the existing Full SSL option. This new mode prevents on-path attacks by ensuring that Cloudflare validates the certificate chain presented by the web server against its own list of trusted certificate authorities. Changes were upstreamed to nginx to enable origin certificate validation and support SNI for multiple domains behind the same IP over TLS.

Read the original post ↗