Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Manual Nginx TLS hardening keeps TLS settings at your server; delegating visitor-facing TLS to an edge provider moves that part of the policy, but does not remove the need to secure the edge-to-origin connection. With a proxy such as Cloudflare, there are two distinct TLS connections to configure: visitor to edge, and edge to origin. The practical choice is where you want to manage each connection—and how you will protect and verify the origin leg.

What changes when TLS is managed at the edge?

With direct Nginx termination, the browser connects to Nginx over HTTPS, and Nginx presents the certificate and applies the TLS settings for that connection. With an edge proxy, the browser connects to the provider, which then makes a separate connection to your origin server. The browser-facing connection being encrypted does not, by itself, establish that the origin connection is encrypted or that the edge has authenticated your origin.

Cloudflare describes its encryption mode as controlling both connections: visitor-to-Cloudflare and Cloudflare-to-origin. The origin leg therefore needs its own encryption and certificate-validation policy. Cloudflare’s encryption-mode documentation explains the available modes.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do the two approaches compare?

Decision area TLS configured directly in Nginx TLS delegated to an edge provider
Visitor-facing protocol policy Configured at the Nginx origin with directives such as ssl_protocols; clients negotiate against that server’s configuration. Managed at the edge for the visitor connection. Edge policy and origin policy are separate decisions.
Certificates and private keys Nginx is configured with certificate and key files. The private key must remain secret but readable by the Nginx master process. The provider handles the visitor-facing TLS endpoint; the origin still needs an appropriate certificate and key for its connection to the edge.
Origin-leg encryption The client connects to Nginx directly over HTTPS. Depends on the selected edge mode. In Cloudflare Full mode, the origin connection follows the scheme requested by the visitor; Full (strict) validates the origin certificate and uses HTTPS.
Origin authentication The client validates the certificate presented by Nginx. Depends on edge policy. Cloudflare Full does not validate the origin certificate; Full (strict) does.
Where policy is changed Nginx configuration and its deployment lifecycle. Provider settings for the visitor-facing policy, plus origin configuration and edge-to-origin settings.
Typical operational risk Version-incompatible directives, certificate-chain mistakes, or incorrect key permissions can disrupt the TLS handshake. Misconfigured origin TLS or an invalid certificate can break the edge-to-origin handshake; proxy bypass paths can also expose an origin that was not secured for direct access.

What should you configure in Nginx?

Nginx’s official HTTPS guide illustrates a server block with HTTPS listening, certificate and key paths, TLS 1.2 and TLS 1.3, and a cipher expression:

server {
    listen              443 ssl;
    server_name         www.example.com;
    ssl_certificate     www.example.com.crt;
    ssl_certificate_key www.example.com.key;
    ssl_protocols       TLSv1.2 TLSv1.3;
    ssl_ciphers         HIGH:!aNULL:!MD5;
}

This is an example from the guide, not a universally optimal cipher policy. Nginx notes that defaults have changed over time, so check the deployed Nginx and OpenSSL versions before adopting a configuration. The SSL module depends on OpenSSL; when it is not included by default, Nginx must be built with --with-http_ssl_module. TLS 1.3 support also depends on a sufficiently recent OpenSSL version. Consult the Nginx HTTPS configuration guide and the Nginx SSL module reference for the directives and compatibility details.

Handle certificate files and keys separately

The certificate is public; the private key is secret. Restrict access to the key while ensuring the Nginx master process can read it. When configuring a certificate chain, place the primary certificate before the intermediate certificates, as specified in the Nginx SSL module documentation.

Rank #2
40 Pcs/20 Set Rack Mount Screws and Cage Nuts for Server Rack Cabinet, Black Carbon Steel M6 x 20 mm Screws with Nylon Washers and Cage Nuts, Rack Mount Hardware for Server Racks/Shelves/Cabinets
  • Durable Carbon Steel: Rack mount screws and cage nuts are made of high-quality carbon steel with a black finish for high strength and dependable durability.
  • Easy Installation: Clear metric threads and uniform pitch for better grip. Nylon washers help secure screws and protect equipment surfaces.
  • Organized Storage: All parts are packed in a portable storage box for easy organization and access.
  • Wide Compatibility: Fits most square-hole racks and cabinets—ideal for server racks, network cabinets, equipment enclosures, and A/V gear.
  • 20-Set Kit: Includes 20 mounting screws with nylon washers (M6 x 20 mm) and 20 square cage nuts—40 pieces in total—meeting daily install and replacement needs.

Which Cloudflare mode secures the origin?

Cloudflare Full and Full (strict) are not interchangeable. In Full mode, Cloudflare uses the scheme requested by the visitor for its origin connection and does not validate the origin certificate. That means a visitor request made over HTTP can result in an HTTP origin connection, and an HTTPS origin certificate is not authenticated by Cloudflare in this mode.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Full (strict) uses HTTPS to the origin and validates its certificate. Cloudflare says the origin must accept HTTPS on port 443 and present an unexpired certificate issued by a public CA or Cloudflare Origin CA, with a hostname matching the requested or target hostname. A certificate or setup problem can result in a 526 error. See Cloudflare’s Full (strict) requirements.

Cloudflare recommends Full (strict) whenever possible, subject to its documented exception for Enterprise customers using the stricter SSL-Only Origin Pull option. That is Cloudflare product guidance, not a vendor-neutral standard. Its Strict (SSL-Only Origin Pull) documentation describes an Enterprise-only mode that always uses TLS to the origin and validates the certificate.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should you choose and operate the policy?

Choose direct Nginx configuration when

  • You want TLS policy managed in the origin’s configuration and deployment process.
  • You can track the deployed Nginx and OpenSSL versions and maintain certificate files, key permissions, and renewals.
  • Your architecture does not require an edge proxy to terminate visitor-facing TLS.

Choose edge delegation when

  • You want visitor-facing TLS policy managed centrally by the edge provider.
  • You can separately configure and monitor the edge-to-origin connection.
  • You have accounted for direct-to-origin or other bypass routes, not just traffic that passes through the edge.

For either approach, map the two connections and assign an explicit policy to each. If using Cloudflare, Full (strict) is the mode that validates the origin certificate; ensure the origin meets its certificate and HTTPS requirements before switching. After changes, check the relevant Nginx configuration and certificate chain, confirm requests reach the intended endpoint, and investigate handshake failures, redirect loops, or mixed-content issues if they appear. Cloudflare notes that mixed content or redirect loops may require adjustment in some deployments.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.