---
title: SSL
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/terraform)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# SSL

#### SSLCertificate Packs

#### resource cloudflare\_certificate\_pack

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

certificate\_authority: String

Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities).

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificate_authority>)

type: String

Type of certificate pack.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20type>)

validation\_method: String

Validation Method selected for the order.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_method>)

validity\_days: Int64

Validity Days selected for the order.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validity_days>)

##### optional Expand Collapse

cloudflare\_branding?: Bool

Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20cloudflare_branding>)

hosts?: Set\[String]

Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20hosts>)

##### computed Expand Collapse

id: String

The unique identifier for a certificate\_pack.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

primary\_certificate: String

Identifier of the primary certificate in a pack.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20primary_certificate>)

status: String

Status of certificate pack.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20status>)

<details>

<summary>

certificates: List\[Attributes]

Array of certificates in this pack.

</summary>

id: String

Certificate identifier.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20id">Link to this property</a>

hosts: List\[String]

Hostnames covered by this certificate.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20hosts">Link to this property</a>

status: String

Certificate status.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20status">Link to this property</a>

bundle\_method: String

Certificate bundle method.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20bundle_method">Link to this property</a>

expires\_on: Time

When the certificate from the authority expires.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20expires_on">Link to this property</a>

<details>

<summary>

geo\_restrictions: Attributes

Specify the region where your private key can be held locally.

</summary>

label: String

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20geo_restrictions%20%3E%20(attribute)%20label">Link to this property</a>

</details>

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20geo_restrictions">Link to this property</a>

issuer: String

The certificate authority that issued the certificate.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20issuer">Link to this property</a>

modified\_on: Time

When the certificate was last modified.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20modified_on">Link to this property</a>

priority: Float64

The order/priority in which the certificate will be used.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20priority">Link to this property</a>

signature: String

The type of hash used for the certificate.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20signature">Link to this property</a>

uploaded\_on: Time

When the certificate was uploaded to Cloudflare.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20uploaded_on">Link to this property</a>

zone\_id: String

Identifier.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20zone_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20certificates>)

<details>

<summary>

dcv\_delegation\_records: List\[Attributes]

DCV Delegation records for domain validation.

</summary>

cname: String

The CNAME record hostname for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20cname">Link to this property</a>

cname\_target: String

The CNAME record target value for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20cname_target">Link to this property</a>

emails: List\[String]

The set of email addresses that the certificate authority (CA) will use to complete domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20emails">Link to this property</a>

http\_body: String

The content that the certificate authority (CA) will expect to find at the http\_url during the domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20http_body">Link to this property</a>

http\_url: String

The url that will be checked during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20http_url">Link to this property</a>

status: String

Status of the validation record.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20status">Link to this property</a>

txt\_name: String

The hostname that the certificate authority (CA) will check for a TXT record during domain validation .

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20txt_name">Link to this property</a>

txt\_value: String

The TXT record that the certificate authority (CA) will check during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20txt_value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dcv_delegation_records>)

<details>

<summary>

validation\_errors: List\[Attributes]

Domain validation errors that have been received by the certificate authority (CA).

</summary>

message: String

A domain validation error.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_errors%20%3E%20(attribute)%20message">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_errors>)

<details>

<summary>

validation\_records: List\[Attributes]

Certificates’ validation records.

</summary>

cname: String

The CNAME record hostname for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20cname">Link to this property</a>

cname\_target: String

The CNAME record target value for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20cname_target">Link to this property</a>

emails: List\[String]

The set of email addresses that the certificate authority (CA) will use to complete domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20emails">Link to this property</a>

http\_body: String

The content that the certificate authority (CA) will expect to find at the http\_url during the domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20http_body">Link to this property</a>

http\_url: String

The url that will be checked during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20http_url">Link to this property</a>

status: String

Status of the validation record.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20status">Link to this property</a>

txt\_name: String

The hostname that the certificate authority (CA) will check for a TXT record during domain validation .

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20txt_name">Link to this property</a>

txt\_value: String

The TXT record that the certificate authority (CA) will check during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20txt_value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20validation_records>)

### cloudflare\_certificate\_pack

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_certificate_pack" "example_certificate_pack" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  certificate_authority = "lets_encrypt"
  hosts = ["example.com", "*.example.com", "www.example.com"]
  type = "advanced"
  validation_method = "txt"
  validity_days = 14
  cloudflare_branding = false
}
```

#### data cloudflare\_certificate\_pack

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

certificate\_pack\_id?: String

The unique identifier for a certificate\_pack.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificate_pack_id>)

<details>

<summary>

filter?: Attributes

</summary>

deploy?: String

Specify the deployment environment for the certificate packs.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20deploy">Link to this property</a>

status?: String

Include Certificate Packs of all statuses, not just active ones.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

The unique identifier for a certificate\_pack.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

certificate\_authority: String

Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities).

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificate_authority>)

cloudflare\_branding: Bool

Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20cloudflare_branding>)

primary\_certificate: String

Identifier of the primary certificate in a pack.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20primary_certificate>)

status: String

Status of certificate pack.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20status>)

type: String

Type of certificate pack.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20type>)

validation\_method: String

Validation Method selected for the order.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_method>)

validity\_days: Int64

Validity Days selected for the order.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validity_days>)

hosts: Set\[String]

Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20hosts>)

<details>

<summary>

certificates: List\[Attributes]

Array of certificates in this pack.

</summary>

id: String

Certificate identifier.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20id">Link to this property</a>

hosts: List\[String]

Hostnames covered by this certificate.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20hosts">Link to this property</a>

status: String

Certificate status.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20status">Link to this property</a>

bundle\_method: String

Certificate bundle method.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20bundle_method">Link to this property</a>

expires\_on: Time

When the certificate from the authority expires.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20expires_on">Link to this property</a>

<details>

<summary>

geo\_restrictions: Attributes

Specify the region where your private key can be held locally.

</summary>

label: String

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20geo_restrictions%20%3E%20(attribute)%20label">Link to this property</a>

</details>

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20geo_restrictions">Link to this property</a>

issuer: String

The certificate authority that issued the certificate.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20issuer">Link to this property</a>

modified\_on: Time

When the certificate was last modified.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20modified_on">Link to this property</a>

priority: Float64

The order/priority in which the certificate will be used.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20priority">Link to this property</a>

signature: String

The type of hash used for the certificate.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20signature">Link to this property</a>

uploaded\_on: Time

When the certificate was uploaded to Cloudflare.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20uploaded_on">Link to this property</a>

zone\_id: String

Identifier.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20zone_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20certificates>)

<details>

<summary>

dcv\_delegation\_records: List\[Attributes]

DCV Delegation records for domain validation.

</summary>

cname: String

The CNAME record hostname for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20cname">Link to this property</a>

cname\_target: String

The CNAME record target value for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20cname_target">Link to this property</a>

emails: List\[String]

The set of email addresses that the certificate authority (CA) will use to complete domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20emails">Link to this property</a>

http\_body: String

The content that the certificate authority (CA) will expect to find at the http\_url during the domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20http_body">Link to this property</a>

http\_url: String

The url that will be checked during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20http_url">Link to this property</a>

status: String

Status of the validation record.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20status">Link to this property</a>

txt\_name: String

The hostname that the certificate authority (CA) will check for a TXT record during domain validation .

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20txt_name">Link to this property</a>

txt\_value: String

The TXT record that the certificate authority (CA) will check during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20txt_value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dcv_delegation_records>)

<details>

<summary>

validation\_errors: List\[Attributes]

Domain validation errors that have been received by the certificate authority (CA).

</summary>

message: String

A domain validation error.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_errors%20%3E%20(attribute)%20message">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_errors>)

<details>

<summary>

validation\_records: List\[Attributes]

Certificates’ validation records.

</summary>

cname: String

The CNAME record hostname for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20cname">Link to this property</a>

cname\_target: String

The CNAME record target value for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20cname_target">Link to this property</a>

emails: List\[String]

The set of email addresses that the certificate authority (CA) will use to complete domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20emails">Link to this property</a>

http\_body: String

The content that the certificate authority (CA) will expect to find at the http\_url during the domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20http_body">Link to this property</a>

http\_url: String

The url that will be checked during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20http_url">Link to this property</a>

status: String

Status of the validation record.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20status">Link to this property</a>

txt\_name: String

The hostname that the certificate authority (CA) will check for a TXT record during domain validation .

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20txt_name">Link to this property</a>

txt\_value: String

The TXT record that the certificate authority (CA) will check during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20txt_value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20validation_records>)

### cloudflare\_certificate\_pack

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_certificate_pack" "example_certificate_pack" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  certificate_pack_id = "3822ff90-ea29-44df-9e55-21300bb9419b"
}
```

#### data cloudflare\_certificate\_packs

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

deploy?: String

Specify the deployment environment for the certificate packs.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20deploy>)

status?: String

Include Certificate Packs of all statuses, not just active ones.

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20status>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The unique identifier for a certificate\_pack.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

certificates: List\[Attributes]

Array of certificates in this pack.

</summary>

id: String

Certificate identifier.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20id">Link to this property</a>

hosts: List\[String]

Hostnames covered by this certificate.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20hosts">Link to this property</a>

status: String

Certificate status.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20status">Link to this property</a>

bundle\_method: String

Certificate bundle method.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20bundle_method">Link to this property</a>

expires\_on: Time

When the certificate from the authority expires.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20expires_on">Link to this property</a>

<details>

<summary>

geo\_restrictions: Attributes

Specify the region where your private key can be held locally.

</summary>

label: String

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20geo_restrictions%20%3E%20(attribute)%20label">Link to this property</a>

</details>

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20geo_restrictions">Link to this property</a>

issuer: String

The certificate authority that issued the certificate.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20issuer">Link to this property</a>

modified\_on: Time

When the certificate was last modified.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20modified_on">Link to this property</a>

priority: Float64

The order/priority in which the certificate will be used.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20priority">Link to this property</a>

signature: String

The type of hash used for the certificate.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20signature">Link to this property</a>

uploaded\_on: Time

When the certificate was uploaded to Cloudflare.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20uploaded_on">Link to this property</a>

zone\_id: String

Identifier.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates%20%3E%20(attribute)%20zone_id">Link to this property</a>

</details>

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificates">Link to this property</a>

hosts: Set\[String]

Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20hosts">Link to this property</a>

status: String

Status of certificate pack.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20status">Link to this property</a>

type: String

Type of certificate pack.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20type">Link to this property</a>

certificate\_authority: String

Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions <a href="https://developers.cloudflare.com/ssl/reference/certificate-authorities">see this page for more details</a>.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20certificate_authority">Link to this property</a>

cloudflare\_branding: Bool

Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20cloudflare_branding">Link to this property</a>

<details>

<summary>

dcv\_delegation\_records: List\[Attributes]

DCV Delegation records for domain validation.

</summary>

cname: String

The CNAME record hostname for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20cname">Link to this property</a>

cname\_target: String

The CNAME record target value for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20cname_target">Link to this property</a>

emails: List\[String]

The set of email addresses that the certificate authority (CA) will use to complete domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20emails">Link to this property</a>

http\_body: String

The content that the certificate authority (CA) will expect to find at the http\_url during the domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20http_body">Link to this property</a>

http\_url: String

The url that will be checked during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20http_url">Link to this property</a>

status: String

Status of the validation record.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20status">Link to this property</a>

txt\_name: String

The hostname that the certificate authority (CA) will check for a TXT record during domain validation .

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20txt_name">Link to this property</a>

txt\_value: String

The TXT record that the certificate authority (CA) will check during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dcv_delegation_records%20%3E%20(attribute)%20txt_value">Link to this property</a>

</details>

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dcv_delegation_records">Link to this property</a>

primary\_certificate: String

Identifier of the primary certificate in a pack.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20primary_certificate">Link to this property</a>

<details>

<summary>

validation\_errors: List\[Attributes]

Domain validation errors that have been received by the certificate authority (CA).

</summary>

message: String

A domain validation error.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_errors%20%3E%20(attribute)%20message">Link to this property</a>

</details>

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_errors">Link to this property</a>

validation\_method: String

Validation Method selected for the order.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_method">Link to this property</a>

<details>

<summary>

validation\_records: List\[Attributes]

Certificates’ validation records.

</summary>

cname: String

The CNAME record hostname for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20cname">Link to this property</a>

cname\_target: String

The CNAME record target value for DCV delegation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20cname_target">Link to this property</a>

emails: List\[String]

The set of email addresses that the certificate authority (CA) will use to complete domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20emails">Link to this property</a>

http\_body: String

The content that the certificate authority (CA) will expect to find at the http\_url during the domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20http_body">Link to this property</a>

http\_url: String

The url that will be checked during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20http_url">Link to this property</a>

status: String

Status of the validation record.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20status">Link to this property</a>

txt\_name: String

The hostname that the certificate authority (CA) will check for a TXT record during domain validation .

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20txt_name">Link to this property</a>

txt\_value: String

The TXT record that the certificate authority (CA) will check during domain validation.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_records%20%3E%20(attribute)%20txt_value">Link to this property</a>

</details>

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validation_records">Link to this property</a>

validity\_days: Int64

Validity Days selected for the order.

<a href="#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20validity_days">Link to this property</a>

</details>

[Link to this property](<#(resource)%20ssl.certificate_packs%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_certificate\_packs

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_certificate_packs" "example_certificate_packs" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  deploy = "staging"
  status = "all"
}
```

#### SSLAuto Origin TLS Kex

#### resource cloudflare\_zone\_auto\_origin\_tls\_kex

##### required Expand Collapse

zone\_id: String

[Link to this property](<#(resource)%20ssl.auto_origin_tls_kex%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

enabled: Bool

Controls enablement of Auto-Origin TLS KEX selection for the zone.

[Link to this property](<#(resource)%20ssl.auto_origin_tls_kex%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20enabled>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20ssl.auto_origin_tls_kex%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

modified\_on: Time

Last time this setting was modified.

[Link to this property](<#(resource)%20ssl.auto_origin_tls_kex%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_on>)

### cloudflare\_zone\_auto\_origin\_tls\_kex

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zone_auto_origin_tls_kex" "example_zone_auto_origin_tls_kex" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  enabled = true
}
```

#### data cloudflare\_zone\_auto\_origin\_tls\_kex

##### required Expand Collapse

zone\_id: String

[Link to this property](<#(resource)%20ssl.auto_origin_tls_kex%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

id: String

[Link to this property](<#(resource)%20ssl.auto_origin_tls_kex%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

enabled: Bool

Whether Auto-Origin TLS KEX selection is enabled for the zone.

[Link to this property](<#(resource)%20ssl.auto_origin_tls_kex%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20enabled>)

modified\_on: Time

Last time this setting was modified.

[Link to this property](<#(resource)%20ssl.auto_origin_tls_kex%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_on>)

### cloudflare\_zone\_auto\_origin\_tls\_kex

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zone_auto_origin_tls_kex" "example_zone_auto_origin_tls_kex" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
}
```

#### SSLUniversalSettings

#### resource cloudflare\_universal\_ssl\_setting

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20ssl.universal.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

enabled?: Bool

Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates from being ordered. If there are no advanced certificates or custom certificates uploaded for the domain, visitors will be unable to access the domain over HTTPS.

By disabling Universal SSL, you understand that the following Cloudflare settings and preferences will result in visitors being unable to visit your domain unless you have uploaded a custom certificate or purchased an advanced certificate.

- HSTS
- Always Use HTTPS
- Opportunistic Encryption
- Onion Routing
- Any Page Rules redirecting traffic to HTTPS

Similarly, any HTTP redirect to HTTPS at the origin while the Cloudflare proxy is enabled will result in users being unable to visit your site without a valid certificate at Cloudflare’s edge.

If you do not have a valid custom or advanced certificate at Cloudflare’s edge and are unsure if any of the above Cloudflare settings are enabled, or if any HTTP redirects exist at your origin, we advise leaving Universal SSL enabled for your domain.

[Link to this property](<#(resource)%20ssl.universal.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20enabled>)

##### computed Expand Collapse

id: String

Identifier.

[Link to this property](<#(resource)%20ssl.universal.settings%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

### cloudflare\_universal\_ssl\_setting

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_universal_ssl_setting" "example_universal_ssl_setting" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  enabled = true
}
```

#### data cloudflare\_universal\_ssl\_setting

##### required Expand Collapse

zone\_id: String

Identifier.

[Link to this property](<#(resource)%20ssl.universal.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### computed Expand Collapse

id: String

Identifier.

[Link to this property](<#(resource)%20ssl.universal.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

enabled: Bool

Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates from being ordered. If there are no advanced certificates or custom certificates uploaded for the domain, visitors will be unable to access the domain over HTTPS.

By disabling Universal SSL, you understand that the following Cloudflare settings and preferences will result in visitors being unable to visit your domain unless you have uploaded a custom certificate or purchased an advanced certificate.

- HSTS
- Always Use HTTPS
- Opportunistic Encryption
- Onion Routing
- Any Page Rules redirecting traffic to HTTPS

Similarly, any HTTP redirect to HTTPS at the origin while the Cloudflare proxy is enabled will result in users being unable to visit your site without a valid certificate at Cloudflare’s edge.

If you do not have a valid custom or advanced certificate at Cloudflare’s edge and are unsure if any of the above Cloudflare settings are enabled, or if any HTTP redirects exist at your origin, we advise leaving Universal SSL enabled for your domain.

[Link to this property](<#(resource)%20ssl.universal.settings%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20enabled>)

### cloudflare\_universal\_ssl\_setting

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_universal_ssl_setting" "example_universal_ssl_setting" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
}
```