Cloudflare Origin CA not trusted 🟧 Cloudflare

NET::ERR_CERT_AUTHORITY_INVALID with a Cloudflare Origin Certificate (record not proxied)

Cloudflare Origin CA certificates are only trusted by Cloudflare — visitors reaching the origin directly (grey-cloud record, direct IP, another CDN) see an untrusted certificate.

Seen on: Cloudflare

Meaning

Origin certificates are designed for the Cloudflare → origin hop. If the DNS record is DNS-only, or a monitoring tool/API client hits the origin directly, browsers and SDKs reject the certificate.

Common causes

  • DNS record set to DNS only (grey cloud)
  • Clients connecting to the origin IP/hostname directly
  • Subdomain not proxied but using the origin cert
  • Another CDN in front instead of Cloudflare

⚡ Quick fix

  1. Turn the record’s proxy on (orange cloud)
  2. Use a publicly trusted certificate (Let’s Encrypt) for directly accessed hosts
  3. Point clients to the proxied hostname

Detailed fix by platform

Shell

  1. bash
    openssl s_client -connect origin.example.com:443 -servername origin.example.com </dev/null 2>/dev/null | openssl x509 -noout -issuer
    # issuer "CloudFlare Origin SSL Certificate Authority" = only trusted by Cloudflare

How to diagnose

  1. Proxy — Orange or grey cloud?
  2. Issuer — Origin CA?
  3. Client — Direct to origin?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.