---
title: Custom Certificates
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/terraform)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Custom Certificates

#### resource cloudflare\_custom\_ssl

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

certificate: String

The zone’s SSL certificate or certificate and the intermediate(s).

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificate>)

##### optional Expand Collapse

type?: String

The type ‘legacy\_custom’ enables support for legacy clients which do not include SNI in the TLS handshake.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20type>)

custom\_csr\_id?: String

The identifier for the Custom CSR that was used.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20custom_csr_id>)

policy?: String

Specify the policy that determines the region where your private key will be held locally. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Any combination of countries, specified by their two letter country code ([https://en.wikipedia.org/wiki/ISO\_3166-1\_alpha-2#Officially\_assigned\_code\_elements](https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2#Officially_assigned_code_elements)) can be chosen, such as ‘country: IN’, as well as ‘region: EU’ which refers to the EU region. If there are too few data centers satisfying the policy, it will be rejected. Note: The API accepts this field as either “policy” or “policy\_restrictions” in requests. Responses return this field as “policy\_restrictions”.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policy>)

private\_key?: String

The zone’s private key. Not required if custom\_csr\_id is provided, in which case the private key is retrieved from the CSR record held by Cloudflare.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20private_key>)

<details>

<summary>

geo\_restrictions?: Attributes

Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.

</summary>

label?: String

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20geo_restrictions%20%3E%20(attribute)%20label">Link to this property</a>

</details>

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20geo_restrictions>)

bundle\_method?: String

A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20bundle_method>)

deploy?: String

The environment to deploy the certificate to, defaults to production.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20deploy>)

##### computed Expand Collapse

id: String

Custom certificate identifier tag.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

expires\_on: Time

When the certificate from the authority expires.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20expires_on>)

issuer: String

The certificate authority that issued the certificate.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20issuer>)

modified\_on: Time

When the certificate was last modified.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_on>)

policy\_restrictions: String

The policy restrictions returned by the API. This field is returned in responses when a policy has been set. The API accepts the “policy” field in requests but returns this field as “policy\_restrictions” in responses.

Specifies the region(s) where your private key can be held locally for optimal TLS performance. Format is a boolean expression, for example: “(country: US) or (region: EU)”

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20policy_restrictions>)

priority: Float64

The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping ‘legacy\_custom’ certificates, but ‘legacy\_custom’ certificates will always supercede ‘sni\_custom’ certificates.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20priority>)

signature: String

The type of hash used for the certificate.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20signature>)

status: String

Status of the zone’s custom SSL.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20status>)

uploaded\_on: Time

When the certificate was uploaded to Cloudflare.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20uploaded_on>)

hosts: List\[String]

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20hosts>)

<details>

<summary>

keyless\_server: Attributes

</summary>

id: String

Keyless certificate identifier tag.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20id">Link to this property</a>

created\_on: Time

When the Keyless SSL was created.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20created_on">Link to this property</a>

enabled: Bool

Whether or not the Keyless SSL is on or off.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20enabled">Link to this property</a>

host: String

The keyless SSL name.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20host">Link to this property</a>

modified\_on: Time

When the Keyless SSL was last modified.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20modified_on">Link to this property</a>

name: String

The keyless SSL name.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20name">Link to this property</a>

permissions: List\[String]

Available permissions for the Keyless SSL for the current user requesting the item.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20permissions">Link to this property</a>

port: Float64

The keyless SSL port used to communicate between Cloudflare and the client’s Keyless SSL server.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20port">Link to this property</a>

status: String

Status of the Keyless SSL.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20status">Link to this property</a>

<details>

<summary>

tunnel: Attributes

Configuration for using Keyless SSL through a Cloudflare Tunnel.

</summary>

private\_ip: String

Private IP of the Key Server Host.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20tunnel%20%3E%20(attribute)%20private_ip">Link to this property</a>

vnet\_id: String

Cloudflare Tunnel Virtual Network ID.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20tunnel%20%3E%20(attribute)%20vnet_id">Link to this property</a>

</details>

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20tunnel">Link to this property</a>

</details>

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20keyless_server>)

### cloudflare\_custom\_ssl

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_custom_ssl" "example_custom_ssl" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  certificate = <<EOT
  -----BEGIN CERTIFICATE-----
  MIIDtTCCAp2gAwIBAgIJAMHAwfXZ5/PWMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNV
  BAYTAkFVMRMwEQYDVQQIEwpTb21lLVN0YXRlMSEwHwYDVQQKExhJbnRlcm5ldCBX
  aWRnaXRzIFB0eSBMdGQwHhcNMTYwODI0MTY0MzAxWhcNMTYxMTIyMTY0MzAxWjBF
  MQswCQYDVQQGEwJBVTETMBEGA1UECBMKU29tZS1TdGF0ZTEhMB8GA1UEChMYSW50
  ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB
  CgKCAQEAwQHoetcl9+5ikGzV6cMzWtWPJHqXT3wpbEkRU9Yz7lgvddmGdtcGbg/1
  CGZu0jJGkMoppoUo4c3dts3iwqRYmBikUP77wwY2QGmDZw2FvkJCJlKnabIRuGvB
  KwzESIXgKk2016aTP6/dAjEHyo6SeoK8lkIySUvK0fyOVlsiEsCmOpidtnKX/a+5
  0GjB79CJH4ER2lLVZnhePFR/zUOyPxZQQ4naHf7yu/b5jhO0f8fwt+pyFxIXjbEI
  dZliWRkRMtzrHOJIhrmJ2A1J7iOrirbbwillwjjNVUWPf3IJ3M12S9pEewooaeO2
  izNTERcG9HzAacbVRn2Y2SWIyT/18QIDAQABo4GnMIGkMB0GA1UdDgQWBBT/LbE4
  9rWf288N6sJA5BRb6FJIGDB1BgNVHSMEbjBsgBT/LbE49rWf288N6sJA5BRb6FJI
  GKFJpEcwRTELMAkGA1UEBhMCQVUxEzARBgNVBAgTClNvbWUtU3RhdGUxITAfBgNV
  BAoTGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZIIJAMHAwfXZ5/PWMAwGA1UdEwQF
  MAMBAf8wDQYJKoZIhvcNAQELBQADggEBAHHFwl0tH0quUYZYO0dZYt4R7SJ0pCm2
  2satiyzHl4OnXcHDpekAo7/a09c6Lz6AU83cKy/+x3/djYHXWba7HpEu0dR3ugQP
  Mlr4zrhd9xKZ0KZKiYmtJH+ak4OM4L3FbT0owUZPyjLSlhMtJVcoRp5CJsjAMBUG
  SvD8RX+T01wzox/Qb+lnnNnOlaWpqu8eoOenybxKp1a9ULzIVvN/LAcc+14vioFq
  2swRWtmocBAs8QR9n4uvbpiYvS8eYueDCWMM4fvFfBhaDZ3N9IbtySh3SpFdQDhw
  YbjM2rxXiyLGxB4Bol7QTv4zHif7Zt89FReT/NBy4rzaskDJY5L6xmY=
  -----END CERTIFICATE-----

  EOT
  bundle_method = "ubiquitous"
  custom_csr_id = "7b163417-1d2b-4c84-a38a-2fb7a0cd7752"
  deploy = "staging"
  geo_restrictions = {
    label = "us"
  }
  policy = "(country: US) or (region: EU)"
  private_key = <<EOT
  -----BEGIN RSA PRIVATE KEY-----
  MIIEowIBAAKCAQEAwQHoetcl9+5ikGzV6cMzWtWPJHqXT3wpbEkRU9Yz7lgvddmG
  dtcGbg/1CGZu0jJGkMoppoUo4c3dts3iwqRYmBikUP77wwY2QGmDZw2FvkJCJlKn
  abIRuGvBKwzESIXgKk2016aTP6/dAjEHyo6SeoK8lkIySUvK0fyOVlsiEsCmOpid
  tnKX/a+50GjB79CJH4ER2lLVZnhePFR/zUOyPxZQQ4naHf7yu/b5jhO0f8fwt+py
  FxIXjbEIdZliWRkRMtzrHOJIhrmJ2A1J7iOrirbbwillwjjNVUWPf3IJ3M12S9pE
  ewooaeO2izNTERcG9HzAacbVRn2Y2SWIyT/18QIDAQABAoIBACbhTYXBZYKmYPCb
  HBR1IBlCQA2nLGf0qRuJNJZg5iEzXows/6tc8YymZkQE7nolapWsQ+upk2y5Xdp/
  axiuprIs9JzkYK8Ox0r+dlwCG1kSW+UAbX0bQ/qUqlsTvU6muVuMP8vZYHxJ3wmb
  +ufRBKztPTQ/rYWaYQcgC0RWI20HTFBMxlTAyNxYNWzX7RKFkGVVyB9RsAtmcc8g
  +j4OdosbfNoJPS0HeIfNpAznDfHKdxDk2Yc1tV6RHBrC1ynyLE9+TaflIAdo2MVv
  KLMLq51GqYKtgJFIlBRPQqKoyXdz3fGvXrTkf/WY9QNq0J1Vk5ERePZ54mN8iZB7
  9lwy/AkCgYEA6FXzosxswaJ2wQLeoYc7ceaweX/SwTvxHgXzRyJIIT0eJWgx13Wo
  /WA3Iziimsjf6qE+SI/8laxPp2A86VMaIt3Z3mJN/CqSVGw8LK2AQst+OwdPyDMu
  iacE8lj/IFGC8mwNUAb9CzGU3JpU4PxxGFjS/eMtGeRXCWkK4NE+G08CgYEA1Kp9
  N2JrVlqUz+gAX+LPmE9OEMAS9WQSQsfCHGogIFDGGcNf7+uwBM7GAaSJIP01zcoe
  VAgWdzXCv3FLhsaZoJ6RyLOLay5phbu1iaTr4UNYm5WtYTzMzqh8l1+MFFDl9xDB
  vULuCIIrglM5MeS/qnSg1uMoH2oVPj9TVst/ir8CgYEAxrI7Ws9Zc4Bt70N1As+U
  lySjaEVZCMkqvHJ6TCuVZFfQoE0r0whdLdRLU2PsLFP+q7qaeZQqgBaNSKeVcDYR
  9B+nY/jOmQoPewPVsp/vQTCnE/R81spu0mp0YI6cIheT1Z9zAy322svcc43JaWB7
  mEbeqyLOP4Z4qSOcmghZBSECgYACvR9Xs0DGn+wCsW4vze/2ei77MD4OQvepPIFX
  dFZtlBy5ADcgE9z0cuVB6CiL8DbdK5kwY9pGNr8HUCI03iHkW6Zs+0L0YmihfEVe
  PG19PSzK9CaDdhD9KFZSbLyVFmWfxOt50H7YRTTiPMgjyFpfi5j2q348yVT0tEQS
  fhRqaQKBgAcWPokmJ7EbYQGeMbS7HC8eWO/RyamlnSffdCdSc7ue3zdVJxpAkQ8W
  qu80pEIF6raIQfAf8MXiiZ7auFOSnHQTXUbhCpvDLKi0Mwq3G8Pl07l+2s6dQG6T
  lv6XTQaMyf6n1yjzL+fzDrH3qXMxHMO/b13EePXpDMpY7HQpoLDi
  -----END RSA PRIVATE KEY-----

  EOT
  type = "sni_custom"
}
```

#### data cloudflare\_custom\_ssl

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

custom\_certificate\_id?: String

Custom certificate identifier tag.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20custom_certificate_id>)

<details>

<summary>

filter?: Attributes

</summary>

match?: String

Whether to match all search requirements or at least one (any).

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20match">Link to this property</a>

status?: String

Status of the zone’s custom SSL.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

Custom certificate identifier tag.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

bundle\_method: String

A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20bundle_method>)

custom\_csr\_id: String

The identifier for the Custom CSR that was used.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20custom_csr_id>)

expires\_on: Time

When the certificate from the authority expires.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20expires_on>)

issuer: String

The certificate authority that issued the certificate.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20issuer>)

modified\_on: Time

When the certificate was last modified.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_on>)

policy\_restrictions: String

The policy restrictions returned by the API. This field is returned in responses when a policy has been set. The API accepts the “policy” field in requests but returns this field as “policy\_restrictions” in responses.

Specifies the region(s) where your private key can be held locally for optimal TLS performance. Format is a boolean expression, for example: “(country: US) or (region: EU)”

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20policy_restrictions>)

priority: Float64

The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping ‘legacy\_custom’ certificates, but ‘legacy\_custom’ certificates will always supercede ‘sni\_custom’ certificates.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20priority>)

signature: String

The type of hash used for the certificate.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20signature>)

status: String

Status of the zone’s custom SSL.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20status>)

uploaded\_on: Time

When the certificate was uploaded to Cloudflare.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20uploaded_on>)

hosts: List\[String]

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20hosts>)

<details>

<summary>

geo\_restrictions: Attributes

Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.

</summary>

label: String

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20geo_restrictions%20%3E%20(attribute)%20label">Link to this property</a>

</details>

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20geo_restrictions>)

<details>

<summary>

keyless\_server: Attributes

</summary>

id: String

Keyless certificate identifier tag.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20id">Link to this property</a>

created\_on: Time

When the Keyless SSL was created.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20created_on">Link to this property</a>

enabled: Bool

Whether or not the Keyless SSL is on or off.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20enabled">Link to this property</a>

host: String

The keyless SSL name.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20host">Link to this property</a>

modified\_on: Time

When the Keyless SSL was last modified.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20modified_on">Link to this property</a>

name: String

The keyless SSL name.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20name">Link to this property</a>

permissions: List\[String]

Available permissions for the Keyless SSL for the current user requesting the item.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20permissions">Link to this property</a>

port: Float64

The keyless SSL port used to communicate between Cloudflare and the client’s Keyless SSL server.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20port">Link to this property</a>

status: String

Status of the Keyless SSL.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20status">Link to this property</a>

<details>

<summary>

tunnel: Attributes

Configuration for using Keyless SSL through a Cloudflare Tunnel.

</summary>

private\_ip: String

Private IP of the Key Server Host.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20tunnel%20%3E%20(attribute)%20private_ip">Link to this property</a>

vnet\_id: String

Cloudflare Tunnel Virtual Network ID.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20tunnel%20%3E%20(attribute)%20vnet_id">Link to this property</a>

</details>

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20tunnel">Link to this property</a>

</details>

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20keyless_server>)

### cloudflare\_custom\_ssl

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_custom_ssl" "example_custom_ssl" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  custom_certificate_id = "2458ce5a-0c35-4c7f-82c7-8e9487d3ff60"
}
```

#### data cloudflare\_custom\_ssls

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

status?: String

Status of the zone’s custom SSL.

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20status>)

match?: String

Whether to match all search requirements or at least one (any).

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20match>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

Custom certificate identifier tag.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

zone\_id: String

Identifier.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20zone_id">Link to this property</a>

bundle\_method: String

A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20bundle_method">Link to this property</a>

custom\_csr\_id: String

The identifier for the Custom CSR that was used.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20custom_csr_id">Link to this property</a>

expires\_on: Time

When the certificate from the authority expires.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20expires_on">Link to this property</a>

<details>

<summary>

geo\_restrictions: Attributes

Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.

</summary>

label: String

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20geo_restrictions%20%3E%20(attribute)%20label">Link to this property</a>

</details>

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20geo_restrictions">Link to this property</a>

hosts: List\[String]

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20hosts">Link to this property</a>

issuer: String

The certificate authority that issued the certificate.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20issuer">Link to this property</a>

<details>

<summary>

keyless\_server: Attributes

</summary>

id: String

Keyless certificate identifier tag.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20id">Link to this property</a>

created\_on: Time

When the Keyless SSL was created.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20created_on">Link to this property</a>

enabled: Bool

Whether or not the Keyless SSL is on or off.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20enabled">Link to this property</a>

host: String

The keyless SSL name.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20host">Link to this property</a>

modified\_on: Time

When the Keyless SSL was last modified.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20modified_on">Link to this property</a>

name: String

The keyless SSL name.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20name">Link to this property</a>

permissions: List\[String]

Available permissions for the Keyless SSL for the current user requesting the item.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20permissions">Link to this property</a>

port: Float64

The keyless SSL port used to communicate between Cloudflare and the client’s Keyless SSL server.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20port">Link to this property</a>

status: String

Status of the Keyless SSL.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20status">Link to this property</a>

<details>

<summary>

tunnel: Attributes

Configuration for using Keyless SSL through a Cloudflare Tunnel.

</summary>

private\_ip: String

Private IP of the Key Server Host.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20tunnel%20%3E%20(attribute)%20private_ip">Link to this property</a>

vnet\_id: String

Cloudflare Tunnel Virtual Network ID.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20tunnel%20%3E%20(attribute)%20vnet_id">Link to this property</a>

</details>

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server%20%3E%20(attribute)%20tunnel">Link to this property</a>

</details>

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20keyless_server">Link to this property</a>

modified\_on: Time

When the certificate was last modified.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_on">Link to this property</a>

policy\_restrictions: String

The policy restrictions returned by the API. This field is returned in responses when a policy has been set. The API accepts the “policy” field in requests but returns this field as “policy\_restrictions” in responses.

Specifies the region(s) where your private key can be held locally for optimal TLS performance. Format is a boolean expression, for example: “(country: US) or (region: EU)”

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20policy_restrictions">Link to this property</a>

priority: Float64

The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping ‘legacy\_custom’ certificates, but ‘legacy\_custom’ certificates will always supercede ‘sni\_custom’ certificates.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20priority">Link to this property</a>

signature: String

The type of hash used for the certificate.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20signature">Link to this property</a>

status: String

Status of the zone’s custom SSL.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20status">Link to this property</a>

uploaded\_on: Time

When the certificate was uploaded to Cloudflare.

<a href="#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20uploaded_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20custom_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_custom\_ssls

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_custom_ssls" "example_custom_ssls" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  status = "active"
}
```