Skip to content

Commit c13dc9b

Browse files
[SSL] Call out editing ciphers causes cert redeployment.mdx (#18982)
* Update customize-cipher-suites.mdx * Update customize-cipher-suites.mdx * Adjust stacked up callouts and remove redundant Note that --------- Co-authored-by: Rebecca Tamachiro <[email protected]>
1 parent 70ac903 commit c13dc9b

File tree

1 file changed

+9
-9
lines changed

1 file changed

+9
-9
lines changed

src/content/docs/ssl/edge-certificates/additional-options/cipher-suites/customize-cipher-suites.mdx

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -18,11 +18,7 @@ You may want to do this to follow specific [recommendations](/ssl/edge-certifica
1818
Customizing cipher suites will not lead to any downtime in your SSL/TLS protection.
1919

2020
:::note
21-
22-
23-
Note that this process only refers to connections [between clients and the Cloudflare network](/ssl/concepts/#edge-certificate). For connections between Cloudflare and your origin server, refer to [Origin server > Cipher suites](/ssl/origin-configuration/cipher-suites/).
24-
25-
21+
This documentation only refers to connections [between clients and the Cloudflare network](/ssl/concepts/#edge-certificate). For connections between Cloudflare and your origin server, refer to [Origin server > Cipher suites](/ssl/origin-configuration/cipher-suites/).
2622
:::
2723

2824
## How it works
@@ -49,6 +45,11 @@ ECDSA cipher suites are prioritized over RSA, and Cloudflare preserves the speci
4945

5046
## Set up
5147

48+
49+
:::note
50+
For guidance around custom hostnames, refer to [TLS settings - Cloudflare for SaaS](/cloudflare-for-platforms/cloudflare-for-saas/security/certificate-management/enforce-mtls/#cipher-suites).
51+
:::
52+
5253
### Before you begin
5354

5455
Note that:
@@ -70,9 +71,8 @@ Note that:
7071

7172
4. Make an API call to either the [Edit zone setting](/api/resources/zones/subresources/settings/methods/edit/) endpoint or the [Edit TLS setting for hostname](/api/resources/hostnames/subresources/settings/subresources/tls/methods/update/) endpoint, specifying `ciphers` in the URL. List your array of chosen cipher suites in the `value` field.
7273

73-
:::caution
74-
75-
For guidance around custom hostnames, refer to [TLS settings - Cloudflare for SaaS](/cloudflare-for-platforms/cloudflare-for-saas/security/certificate-management/enforce-mtls/#cipher-suites).
74+
:::note
75+
Updating the cipher suites will result in certificates being redeployed.
7676
:::
7777

7878
<Tabs> <TabItem label="modern">
@@ -128,7 +128,7 @@ curl --request PATCH \
128128

129129
:::caution
130130

131-
For compliance with PCI DSS, also [enable TLS 1.3](/ssl/edge-certificates/additional-options/tls-13/#enable-tls-13) on your zone and make sure to up your [Minimum TLS version](/ssl/edge-certificates/additional-options/minimum-tls/) to `1.2`.
131+
For compliance with PCI DSS, also [enable TLS 1.3](/ssl/edge-certificates/additional-options/tls-13/#enable-tls-13) on your zone and make sure to up your [Minimum TLS version](/ssl/edge-certificates/additional-options/minimum-tls/) to `1.2`.
132132
:::
133133

134134
</TabItem> <TabItem label="fips-140-2">

0 commit comments

Comments
 (0)