INTEGRITY Cloudflare Docs

Customize cipher suites via dashboard

Cipher suites are a combination of ciphers used to negotiate security settings during the SSL/TLS handshake (and therefore separate from the SSL/TLS protocol).

Prerequisites

Cipher suite customization requires an Advanced Certificate Manager subscription.

If you are a SaaS provider looking to restrict cipher suites for connections to custom hostnames, this can be configured with a Cloudflare for SaaS subscription. Refer to TLS management instead.

Selection modes

When configuring cipher suites via dashboard, you can use three different selection modes:

For any of the modes, you should keep in mind the following configuration conditions. If using the security level or the compliance standard mode, some actions may be blocked and explained referencing these conditions.

Configuration conditions

Steps

  1. In the Cloudflare dashboard, go to the Edge Certificates page.

    Go to Edge Certificates ↗
  2. For the Cipher suites setting select Configure.

  3. Choose a mode to select your cipher suites and select Next.

  4. Select a predefined set of cipher suites or, if you opted for Custom, specify which cipher suites you want to allow. Make sure you are aware of how your selection will interact with Minimum TLS version, TLS 1.3, and the certificate algorithm (ECDSA or RSA).

  5. Select Save to confirm.

Footnotes

  1. When used with TLS 1.3, Modern is the same as PCI DSS.