HTTPS-only for Cloudflare APIs: shutting the door on cleartext traffic
ID: b60b8dbc-de30-5f6a-be73-b0ecc7710575
STIX ID: report--b60b8dbc-de30-5f6a-be73-b0ecc7710575
Feed Name: Cloudflare Blog
Cloudflare announces it is enforcing HTTPS-only for api.cloudflare.com by closing all plaintext HTTP ports at the transport layer to prevent credential exposure, introducing DNS/IP agility and a move away from static IPs, and planning to deprecate non-SNI clients; the company will offer customers an opt-in feature to disable HTTP on their own domains by late 2025, supported by analytics and rollout tooling (Tubular, Topaz, iptables) for safe, scalable deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
