Lộ trình đang học Current learning path

Application Services Application Services

Bảo vệ và tăng tốc website, application và API. Protect and accelerate websites, applications, and APIs.

Về trang lộ trình Track home

Phần 2: SSL/TLS và kết nối origin Part 2: SSL/TLS and origin connection · Bài 1/2 Lesson 1/2

Chọn SSL/TLS mode phù hợp Choose the right SSL/TLS mode

Full (strict) khi origin có cert hợp lệ. Tránh Flexible nếu origin chỉ nhận HTTPS. Kiểm tra redirect HTTP→HTTPS. Use Full (strict) when origin has a valid cert. Avoid Flexible if origin expects HTTPS. Verify HTTP→HTTPS redirects.

Các bước thực hiện Step-by-step

  1. SSL/TLS → Overview: chọn Full (strict) nếu origin có cert hợp lệ. SSL/TLS → Overview: choose Full (strict) when origin has a valid cert.
  2. Tránh Flexible khi origin chỉ chấp nhận HTTPS (gây redirect loop). Avoid Flexible when origin expects HTTPS only (can cause redirect loops).
  3. Bật Always Use HTTPS + Automatic HTTPS Rewrites. Enable Always Use HTTPS + Automatic HTTPS Rewrites.
  4. Test http:// và https:// — không lỗi cert trên browser. Test http:// and https:// — no certificate errors in the browser.

Giải thích chi tiết Detailed explanation

SSL mode quyết định mã hóa giữa user↔Cloudflare và Cloudflare↔origin. Đây là nguồn lỗi phổ biến nhất sau khi bật proxy. SSL mode controls encryption user↔Cloudflare and Cloudflare↔origin. This is the most common issue after enabling proxy.

Mẹo: Tip: Test bằng curl hoặc browser incognito sau mỗi thay đổi mode. Test with curl or an incognito browser after each mode change.

Lưu ý (best practices) Note (best practices)

Để mã hóa end-to-end, dùng Full (strict): cả kết nối visitor→Cloudflare và Cloudflare→origin đều HTTPS, origin cert được xác thực. Bật Always Use HTTPS để chuyển mọi HTTP sang HTTPS. For end-to-end encryption, use Full (strict): both visitor→Cloudflare and Cloudflare→origin use HTTPS with origin certificate validation. Enable Always Use HTTPS to redirect all HTTP to HTTPS.

Nguồn: Source: Enforce HTTPS and encrypt all traffic Enforce HTTPS and encrypt all traffic

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path.

Hướng dẫn giải pháp Solution guide Application Services Application Services

Enforce HTTPS và encrypt all traffic (Free, Pro, và Business) Enforce HTTPS and encrypt all traffic (Free, Pro, and Business)

Cấu hình SSL/TLS encryption from edge to origin, redirect HTTP to HTTPS, and harden your HTTPS setup with HSTS and minimum TLS versions.

Configure SSL/TLS encryption from edge to origin, redirect HTTP to HTTPS, and harden your HTTPS setup with HSTS and minimum TLS versions.

Tìm hiểu thêm Learn more
Tutorial Tutorial Application Services Application Services

3 – Configure HTTPS settings Configure HTTPS settings

Tóm tắt thực hành: Cấu hình HTTPS settings trên Terraform. This tutorial shows how to enable TLS 1.3, Automatic HTTPS Rewrites, and Strict SSL mode using the updated v5 provider.

This tutorial shows how to enable TLS 1.3, Automatic HTTPS Rewrites, and Strict SSL mode using the updated v5 provider.

Tìm hiểu thêm Learn more

Xem thêm ví dụ trong lộ trình → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs

Sản phẩm liên quan Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths