Skip to content

Troubleshooting

Last updated View as MarkdownAgent setup

Resolve a timed out state

If a certificate issuance times out, Cloudflare tells you where in the chain of issuance the timeout occurred: Initializing, Validation, Issuance, Deployment, or Deletion.

To resolve timeout issues, try one or more of the following options:

  • Change the Proxy status of related DNS records to DNS only (gray-clouded) and wait at least a minute. Then, change the Proxy status back to Proxied (orange-clouded).
  • Disable Universal SSL and wait at least a minute. Then, re-enable Universal SSL.
  • Send a PATCH request to the validation endpoint using the same DCV method (API only). Make sure that the --data field is not empty in your request.
  • Review your domain control validation (DCV). Changing the DCV method will restart certificate issuance.

Delete certificates

You can use the API to delete certificates that you no longer want listed on the Cloudflare dashboard.

RSA certificate not available after plan upgrade

If you upgraded your zone from Free to a paid plan and your Universal SSL certificate includes only an ECDSA certificate (no RSA certificate), this is expected behavior. Cloudflare does not automatically re-issue the Universal SSL certificate when you change your plan.

Your RSA certificate will be issued when the certificate pack next renews. To get an RSA certificate sooner, you can:

  • Order an advanced certificate (requires the Advanced Certificate Manager add-on).
  • Disable Universal SSL and then re-enable it. Cloudflare provisions a new certificate pack for your current plan, which on paid plans includes both RSA and ECDSA certificates. While Universal SSL is disabled and until the new certificate is issued, new TLS connections to your zone will fail unless another valid certificate covers your hostnames. Provisioning time is not guaranteed, so plan for this before using this option. Review Disable Universal SSL for settings, such as HSTS and Always Use HTTPS, that can cause errors while Universal SSL is disabled.

For details, refer to Certificate type.

Other issues

For additional troubleshooting help, refer to Troubleshooting SSL errors.

Was this helpful?