---
title: Origin CA Certificates
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/terraform)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Origin CA Certificates

#### resource cloudflare\_origin\_ca\_certificate

##### required Expand Collapse

csr: String

The Certificate Signing Request (CSR). Must be newline-encoded.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20csr>)

request\_type: String

Signature type desired on certificate (“origin-rsa” (rsa), “origin-ecc” (ecdsa), or “keyless-certificate” (for Keyless SSL servers).

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20request_type>)

hostnames: List\[String]

Array of hostnames or wildcard names bound to the certificate. Hostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20hostnames>)

##### optional Expand Collapse

requested\_validity?: Float64

The number of days for which the certificate should be valid.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20requested_validity>)

##### computed Expand Collapse

id: String

The x509 serial number of the Origin CA certificate.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

certificate: String

The Origin CA certificate. Will be newline-encoded.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificate>)

expires\_on: String

When the certificate will expire.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20expires_on>)

### cloudflare\_origin\_ca\_certificate

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_origin_ca_certificate" "example_origin_ca_certificate" {
  csr = <<EOT
  -----BEGIN CERTIFICATE REQUEST-----
  MIICxzCCAa8CAQAwSDELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDVNhbiBGcmFuY2lz
  Y28xCzAJBgNVBAcTAkNBMRQwEgYDVQQDEwtleGFtcGxlLm5ldDCCASIwDQYJKoZI
  hvcNAQEBBQADggEPADCCAQoCggEBALxejtu4b+jPdFeFi6OUsye8TYJQBm3WfCvL
  Hu5EvijMO/4Z2TImwASbwUF7Ir8OLgH+mGlQZeqyNvGoSOMEaZVXcYfpR1hlVak8
  4GGVr+04IGfOCqaBokaBFIwzclGZbzKmLGwIQioNxGfqFm6RGYGA3be2Je2iseBc
  N8GV1wYmvYE0RR+yWweJCTJ157exyRzu7sVxaEW9F87zBQLyOnwXc64rflXslRqi
  g7F7w5IaQYOl8yvmk/jEPCAha7fkiUfEpj4N12+oPRiMvleJF98chxjD4MH39c5I
  uOslULhrWunfh7GB1jwWNA9y44H0snrf+xvoy2TcHmxvma9Eln8CAwEAAaA6MDgG
  CSqGSIb3DQEJDjErMCkwJwYDVR0RBCAwHoILZXhhbXBsZS5uZXSCD3d3dy5leGFt
  cGxlLm5ldDANBgkqhkiG9w0BAQsFAAOCAQEAcBaX6dOnI8ncARrI9ZSF2AJX+8mx
  pTHY2+Y2C0VvrVDGMtbBRH8R9yMbqWtlxeeNGf//LeMkSKSFa4kbpdx226lfui8/
  auRDBTJGx2R1ccUxmLZXx4my0W5iIMxunu+kez+BDlu7bTT2io0uXMRHue4i6quH
  yc5ibxvbJMjR7dqbcanVE10/34oprzXQsJ/VmSuZNXtjbtSKDlmcpw6To/eeAJ+J
  hXykcUihvHyG4A1m2R6qpANBjnA0pHexfwM/SgfzvpbvUg0T1ubmer8BgTwCKIWs
  dcWYTthM51JIqRBfNqy4QcBnX+GY05yltEEswQI55wdiS3CjTTA67sdbcQ==
  -----END CERTIFICATE REQUEST-----
  EOT
  hostnames = ["example.com", "*.example.com", "sub.example.com"]
  request_type = "origin-rsa"
  requested_validity = 5475
}
```

#### data cloudflare\_origin\_ca\_certificate

##### optional Expand Collapse

certificate\_id?: String

The x509 serial number of the Origin CA certificate.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificate_id>)

<details>

<summary>

filter?: Attributes

</summary>

zone\_id: String

Identifier.

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20zone_id">Link to this property</a>

limit?: Int64

Limit to the number of records returned.

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20limit">Link to this property</a>

offset?: Int64

Offset the results.

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20offset">Link to this property</a>

</details>

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

The x509 serial number of the Origin CA certificate.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

certificate: String

The Origin CA certificate. Will be newline-encoded.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificate>)

csr: String

The Certificate Signing Request (CSR). Must be newline-encoded.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20csr>)

expires\_on: String

When the certificate will expire.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20expires_on>)

request\_type: String

Signature type desired on certificate (“origin-rsa” (rsa), “origin-ecc” (ecdsa), or “keyless-certificate” (for Keyless SSL servers).

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20request_type>)

requested\_validity: Float64

The number of days for which the certificate should be valid.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20requested_validity>)

hostnames: List\[String]

Array of hostnames or wildcard names bound to the certificate. Hostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20hostnames>)

### cloudflare\_origin\_ca\_certificate

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_origin_ca_certificate" "example_origin_ca_certificate" {
  certificate_id = "328578533902268680212849205732770752308931942346"
}
```

#### data cloudflare\_origin\_ca\_certificates

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

limit?: Int64

Limit to the number of records returned.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20limit>)

offset?: Int64

Offset the results.

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20offset>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

csr: String

The Certificate Signing Request (CSR). Must be newline-encoded.

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20csr">Link to this property</a>

hostnames: List\[String]

Array of hostnames or wildcard names bound to the certificate. Hostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., <code>example.com</code> or <code>sub.example.com</code>). Wildcards are supported only as a <code>*.</code> prefix for a single level (e.g., <code>*.example.com</code>). Double wildcards (<code>*.*.example.com</code>) and interior wildcards (<code>foo.*.example.com</code>) are not allowed. The wildcard suffix must be a multi-label domain (<code>*.example.com</code> is valid, but <code>*.com</code> is not). Unicode/IDN hostnames are accepted and automatically converted to punycode.

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20hostnames">Link to this property</a>

request\_type: String

Signature type desired on certificate (“origin-rsa” (rsa), “origin-ecc” (ecdsa), or “keyless-certificate” (for Keyless SSL servers).

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20request_type">Link to this property</a>

requested\_validity: Float64

The number of days for which the certificate should be valid.

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20requested_validity">Link to this property</a>

id: String

The x509 serial number of the Origin CA certificate.

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

certificate: String

The Origin CA certificate. Will be newline-encoded.

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificate">Link to this property</a>

expires\_on: String

When the certificate will expire.

<a href="#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20expires_on">Link to this property</a>

</details>

[Link to this property](<#(resource)%20origin_ca_certificates%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_origin\_ca\_certificates

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_origin_ca_certificates" "example_origin_ca_certificates" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  limit = 10
  offset = 10
}
```