Hacker News new | past | comments | ask | show | jobs | submit login

This is common for sites that are behind a TLS-terminating CDN. (They could still be using one between their origin and Cloudflare.)

In general it doesn't matter who issues the certificate as long as they're trusted.




You are correct, however CloudFlare does support supplying your own certificate, and I'd consider it an element of dogfooding to use their own CA on their own site.


Note that you’d either need to hand cloudflare the private key for the cert or use their key server and run it on your infrastructure. You’ll also need to manage the certificates lifecycle. Unless you have a very compelling reason to do so, I doubt it’s worth the effort.


It's also worth mentioning that you can give Cloudflare your own certificate to use if you care what users see. I think this option might require one of the paid Cloudflare plans.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: