Skip to content
Follow
Ubuntu Linux

How to use Cloudflare Origin Certificates with Apache on Ubuntu Linux

Richard
Written by
Richard
May 26, 2019 Updated Aug 15, 2026 5 min read
How to Install Google Chrome on Ubuntu Linux
How to Install Google Chrome on Ubuntu Linux

Cloudflare Origin Certificates secure traffic between Cloudflare and your Apache web server on Ubuntu Linux by creating an encrypted connection. This setup uses a free security key valid for up to 15 years, and it supports wildcard domains like *.example.com to protect all your subdomains at once.

⚡ Quick Answer

Generate a Cloudflare Origin Certificate from your Cloudflare dashboard under the Crypto tab. Select Origin Certificates, then click Create Certificate. Copy the generated certificate and private key, then paste them into respective files on your Ubuntu server.

Full SSL (Strict) mode relies on these certificates to guarantee true end-to-end encryption for your website data. Setting this up stops plain text snooping and keeps visitor information safe on the final hop to your server.

How to sign up for Cloudflare

The first step in this tutorial is to sign up for a Cloudflare account. This guide assumes you already have a registered domain name. If not, please register one before proceeding.

If you already have a Cloudflare account, skip the registration steps below.

https://dash.cloudflare.com/sign-up

Enter an email address and click Create Account.

Cloudflare WordPress setup
cloudflare wordpress setup

After verifying the email, log back into Cloudflare and click Add a Site.

Cloudflare WordPress setup
cloudflare wordpress setup 1

Next, enter the domain name you registered. Cloudflare's service helps speed up and protect the site you add.

Cloudflare WordPress setup
cloudflare wordpress setup 2

Cloudflare queries the domain registrar for existing DNS (Domain Name System) records. If your DNS is online, Cloudflare should find the domain and import the records into its systems.

Cloudflare WordPress setup
cloudflare wordpress setup 3

Finally, select your plan; we'll use the free plan for this tutorial.

Cloudflare WordPress setup
cloudflare wordpress setup 4

Once complete, Cloudflare will provide two nameservers. You'll need to log on to your domain provider's portal. Then, replace your existing nameservers with the ones Cloudflare provides.

Cloudflare setup page showing name server configuration instructions.
cloudflare setup name servers

For example, our example.com site is hosted with Google Domains. Log on to your Google Domains account and select "use custom nameservers."

You'll have the option to enter the nameservers Cloudflare provided. Save your changes when finished.

Cloudflare WordPress Setup
cloudflare wordpress setup 16

After saving your custom nameserver changes, return to your Cloudflare account and wait for Cloudflare to detect them. Depending on your domain provider, DNS changes can take up to an hour to become visible on Cloudflare.

Cloudflare overview page indicating an active SSL/TLS setup.
cloudflare overview active

Once everything is ready, your site status will show as Active.

You should also see your Cloudflare account populated with DNS entries, as shown below. Your DNS records might include more entries than the two displayed.

These two entries are essential for running your website.

Cloudflare WordPress Setup
cloudflare wordpress setup 6

Next, click the Crypto tab and choose to enable Full (strict) SSL. This action should activate SSL for your site.

Cloudflare WordPress Setup
cloudflare wordpress setup 17

While still on the Crypto tab, scroll down to Origin Certificates. Then click the button to create the Certificate.

Use the free TLS certificate signed by Cloudflare, which you will install on your origin server. Origin Certificates are specifically for encryption between Cloudflare and your origin server.

Cloudflare WordPress setup screen for SSL/TLS settings.
cloudflare wordpress setup 8

Next, let Cloudflare generate a private key and a CSR for the domain. Click Next.

WordPress Cloudflare
cloudflare wordpress setup 9

Then, copy and paste these into a text file on your server.

Run the commands below on Ubuntu to create the Private key, Certificate, and Origin pull files (3 files total). Copy and paste the content of each into its respective file, then save.

For the Private key file, execute the command for the private key file, paste the provided key into the editor, and save the file. Repeat this process for the certificate file.

🐧Bash / Shell
sudo nano /etc/ssl/private/cloudflare_key_example.com.pem

For the certificate file, run this command, copy and paste the certificate content into the file, and save it.

🐧Bash / Shell
sudo nano /etc/ssl/certs/cloudflare_example.com.pem

Download the Cloudflare Origin Pull certificate as well. You can find it at the link below:

Zone-Level — Cloudflare certificate

Under Zone-level certificate, expand the certificate button and copy its content.

Next, run the commands below to create an origin-pull-ca.pem file. Paste the certificate content into the file below, and save it.

🐧Bash / Shell
sudo nano /etc/ssl/certs/origin-pull-ca.pem

Once done, you should have three files: cloudflare_key_example.com.pem, cloudflare_example.com.pem, and origin-pull-ca.pem.

We'll use these files in the Apache configuration below.

Cloudflare SSL/TLS setup page with encryption mode selection.
cloudflare wordpress setup 10

Keep these certificate files handy after saving the key, Certificate, and Origin. Continue below.

Still on the Crypto page in your Cloudflare account, enable Always use HTTPS. You can also change settings for HSTS, though it's not required.

Cloudflare SSL/TLS settings for WordPress website security.
cloudflare wordpress setup 11

Next, turn on Authenticated Origin Pulls and Opportunistic Encryption, then proceed.

Cloudflare SSL/TLS certificate settings for Apache on Ubuntu.
cloudflare wordpress setup 12

Then, turn on Automatic HTTPS Rewrites and proceed.

Cloudflare SSL/TLS certificate details for origin server setup.
cloudflare wordpress setup 13

Next, navigate to the Page Rules tab. Create a new rule for your site. Enter the URL and choose Always Use HTTPS.

HTTP://* example.com/*

Always Use HTTPS

Cloudflare dashboard showing active SSL/TLS configuration for origin.
cloudflare wordpress setup 15

Save your settings. You've now completed the Cloudflare setup.

How to configure Apache with Cloudflare

Finally, configure the Apache site configuration file for your website. This file dictates how users access your website content. Run the commands below to create a new configuration file named example.com.

🐧Bash / Shell
sudo nano /etc/apache2/sites-available/example.com.conf

Then copy and paste the content below into the file and save it. Replace the highlighted line with your domain name and directory root location.

Also, reference the certificate files created earlier during the Cloudflare setup.

💻Code
<VirtualHost *:80>
  ServerName example.com
  ServerAlias www.example.com
</VirtualHost>

<VirtualHost *:443>
     Protocols h2 http/1.1
     ServerAdmin admin@example.com
     DocumentRoot /var/www/html/example.com
     ServerName example.com
     ServerAlias www.example.com
    
     SSLEngine on
     SSLCertificateFile /etc/ssl/certs/cloudflare_example.com.pem
     SSLCertificateKeyFile /etc/ssl/private/cloudflare_key_example.com.pem
     SSLCACertificateFile /etc/ssl/certs/origin-pull-ca.pem
     SSLVerifyClient require
     SSLVerifyDepth 1

     <Directory /var/www/html/example.com/>
          Options FollowSymlinks
          AllowOverride All
          Require all granted
     </Directory  ErrorLog ${APACHE_LOG_DIR}/error.log
     CustomLog ${APACHE_LOG_DIR}/access.log combined

</VirtualHost>

Save the file and exit.

How to enable VirtualHost block with Apache

After configuring the server block above, enable it by running the commands below.

🐧Bash / Shell
sudo a2ensite example.com.conf
sudo systemctl restart apache2.service

Then open your browser and navigate to your server's domain name.

That should complete the process!

Conclusion:

This guide covered enabling a Cloudflare origin certificate to secure the connection between Cloudflare and the origin server. If you encounter any errors, please use the comment form below to report them.

How to get Cloudflare origin certificate?

Create an Origin CA certificate Go to the Origin Server page. On the Origin Certificates tab, select Create Certificate. Choose either: Generate private key and CSR with Cloudflare: Private key type can be RSA or ECC.

Was this guide helpful?

Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.

📚 Related Tutorials

How to Install Ghost on Ubuntu Linux with Nginx
CMS How to Install Ghost on Ubuntu Linux with Nginx
How to Install Apache on Ubuntu Linux
Ubuntu Linux How to Install Apache on Ubuntu Linux
How to Re-enable TLS 1.0 and 1.1 on Windows 11
Windows How to Re-enable TLS 1.0 and 1.1 on Windows 11
How to Change Power Mode in Ubuntu Linux
Ubuntu Linux How to Change Power Mode in Ubuntu Linux

0 Comments

  • This tutorial is messed up. You clearly instructing to create3 files: a private key file, a certificate file, and an origin pull certificate. You have given the example to create the private key file as “sudo nano /etc/ssl/private/cloudflare_example.com.pem”, the certificate file as “sudo /etc/ssl/certs/cloudflare_example.com.pem”. However, if you followed the steps on CloudFlare, you should know that you DO NOT get 2 “pem” files. You get a “key” file and a “pem” file. In your example you show a “pem” file for both key and certificate files. This is conflicting, confusing, and frustrating for a person, like me, how is doing this the first time. If you know what you are talking about, please give CORRECT instructions. If you do not, then DO NOT give confusing or otherwise misleading instructions. Thank you.

    Reply
  • Please do the world a favor and STOP writing another tutorial until you are thoroughly familiar with the topic and included ALL steps necessary. Otherwise you just leave people in limbo and frustration.

    SSLEngine on
    Invalid command ‘SSLEngine’, perhaps misspelled or defined by a module not included in the server configuration

    If this is important and required, maybe you should spell this out how to enable it!

    Reply
  • Thank you for the tutorial very details, I think you forgot to mention

    sudo a2enmod ssl

    run the above cmd, if you are getting SSLEngine on
    Invalid command ‘SSLEngine’, perhaps misspelled or defined by a module not included in the server configuration

    Reply
  • Thanks for your help! This guide is perfectly detailed.
    (Sorry for my english)

    Reply
    • No its not…its a mess and has caused lots of problems for my server.
      To be honest the instructor should try it out on a real server.

      Thanks to this tutorial and the SSLEngine on syntax error my apache is stuffed up!!

      Reply
      • I take that all back……..I stuffed it up your tutorial is one of the bets and it works…..except for one typo where “nano” is not specified in the sudo for the cert paste:)

        Keep up the good work :)))))

        Reply
  • Thank
    IOS Broken . Need Del :
    Protocols h2 http:/1.1 —–> Protocols h2 http/1.1

    Reply
  • sudo a2ensite example.com.conf

    : command not found

    this command doesnt work on me using centos 7

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *