• Björn@swg-empire.de
    link
    fedilink
    arrow-up
    3
    ·
    5 months ago

    How can they act as a proxy if they can’t terminate the connection? Or what service does that offer?

    I guess they could filter out some connections based on IP addresses. But is that enough for some customers? Or am I overlooking something?

    • chicken@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      5 months ago

      How can they act as a proxy if they can’t terminate the connection?

      Why wouldn’t they be able to? The DNS record points to Cloudflare’s IP, they forward the traffic to your server’s IP. This is a common choice for self hosting setups because it’s a free service and it is a way to avoid pointing a DNS record at your home IP, which you may not want everyone to know. That doesn’t require decrypting the traffic.

      How this squares with the ddos protection and caching stuff, I’m not sure, but I know I set up SSL locally, did not give Cloudflare the keys, turned off all the options for them to handle it, and everything seems to work.

      • Lee@retrolemmy.com
        link
        fedilink
        arrow-up
        1
        ·
        5 months ago

        You should check the certificate shown to clients when accessing your domain. I think you’ll find that it is not the certificate that you created outside of Cloudflare. Cloudflare doesn’t need your private key as they issue a certificate for your domain to themselves and use that for the connection with the client. The certificate you created is used between Cloudflare and your server. The only option I’m aware to route traffic through Cloudflare where they don’t terminate SSL is an enterprise only feature.