Skip to content

Commit

Permalink
Adjust stacked up callouts and remove redundant Note that
Browse files Browse the repository at this point in the history
  • Loading branch information
RebeccaTamachiro committed Jan 3, 2025
1 parent 24ca965 commit c965b79
Showing 1 changed file with 7 additions and 12 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -18,11 +18,7 @@ You may want to do this to follow specific [recommendations](/ssl/edge-certifica
Customizing cipher suites will not lead to any downtime in your SSL/TLS protection.

:::note


Note that this process only refers to connections [between clients and the Cloudflare network](/ssl/concepts/#edge-certificate). For connections between Cloudflare and your origin server, refer to [Origin server > Cipher suites](/ssl/origin-configuration/cipher-suites/).


This documentation only refers to connections [between clients and the Cloudflare network](/ssl/concepts/#edge-certificate). For connections between Cloudflare and your origin server, refer to [Origin server > Cipher suites](/ssl/origin-configuration/cipher-suites/).
:::

## How it works
Expand All @@ -49,6 +45,11 @@ ECDSA cipher suites are prioritized over RSA, and Cloudflare preserves the speci

## Set up


:::note
For guidance around custom hostnames, refer to [TLS settings - Cloudflare for SaaS](/cloudflare-for-platforms/cloudflare-for-saas/security/certificate-management/enforce-mtls/#cipher-suites).
:::

### Before you begin

Note that:
Expand All @@ -71,15 +72,9 @@ Note that:
4. Make an API call to either the [Edit zone setting](/api/resources/zones/subresources/settings/methods/edit/) endpoint or the [Edit TLS setting for hostname](/api/resources/hostnames/subresources/settings/subresources/tls/methods/update/) endpoint, specifying `ciphers` in the URL. List your array of chosen cipher suites in the `value` field.

:::note

Updating the cipher suites will result in certificates being redeployed.
:::

:::caution

For guidance around custom hostnames, refer to [TLS settings - Cloudflare for SaaS](/cloudflare-for-platforms/cloudflare-for-saas/security/certificate-management/enforce-mtls/#cipher-suites).
:::

<Tabs> <TabItem label="modern">

<Render file="ciphers-api-general-notes" />
Expand Down Expand Up @@ -133,7 +128,7 @@ curl --request PATCH \

:::caution

For compliance with PCI DSS, also [enable TLS 1.3](/ssl/edge-certificates/additional-options/tls-13/#enable-tls-13) on your zone and make sure to up your [Minimum TLS version](/ssl/edge-certificates/additional-options/minimum-tls/) to `1.2`.
For compliance with PCI DSS, also [enable TLS 1.3](/ssl/edge-certificates/additional-options/tls-13/#enable-tls-13) on your zone and make sure to up your [Minimum TLS version](/ssl/edge-certificates/additional-options/minimum-tls/) to `1.2`.
:::

</TabItem> <TabItem label="fips-140-2">
Expand Down

0 comments on commit c965b79

Please sign in to comment.