---
title: Origin TLS Compliance Modes
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/terraform)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Origin TLS Compliance Modes

#### resource cloudflare\_origin\_tls\_compliance\_modes

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

value: List\[String]

List of TLS compliance modes that constrain the key-exchange algorithms Cloudflare may use when establishing the TLS connection to the zone’s origin. Currently supported values are `fips` (FIPS-approved curves) and `pqh` (post-quantum hybrid). Future modes (e.g. `cnsa2`) may be added; clients should treat unknown values as opaque strings. Multiple modes are combined as the intersection of their permitted algorithm lists; selections whose intersection is empty are rejected. An empty list clears the constraint.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20value>)

##### computed Expand Collapse

id: String

Identifier.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

editable: Bool

Whether the setting is editable.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20editable>)

modified\_on: Time

Last time this setting was modified.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_on>)

### cloudflare\_origin\_tls\_compliance\_modes

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_origin_tls_compliance_modes" "example_origin_tls_compliance_modes" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  value = ["fips", "pqh"]
}
```

#### data cloudflare\_origin\_tls\_compliance\_modes

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

id: String

Identifier.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

editable: Bool

Whether the setting is editable.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20editable>)

modified\_on: Time

Last time this setting was modified.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_on>)

value: List\[String]

List of TLS compliance modes that constrain the key-exchange algorithms Cloudflare may use when establishing the TLS connection to the zone’s origin. Currently supported values are `fips` (FIPS-approved curves) and `pqh` (post-quantum hybrid). Future modes (e.g. `cnsa2`) may be added; clients should treat unknown values as opaque strings. Multiple modes are combined as the intersection of their permitted algorithm lists; selections whose intersection is empty are rejected. An empty list clears the constraint.

[Link to this property](<#(resource)%20origin_tls_compliance_modes%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20value>)

### cloudflare\_origin\_tls\_compliance\_modes

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_origin_tls_compliance_modes" "example_origin_tls_compliance_modes" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
}
```