Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you read the comments, the cloudflare guys mention that, like Amazon CloudFront, it is not yet possible to use your own certificate. That means their cost is essentially zero (some CPU time or an SSL accelerator card). They can serve every request from the same endpoint.

It also means their SSL service is useless for CDN because it will induce warnings in the browser. (You may be able to evade the warnings if you add their custom domain as a SAN on your primary certificate, but I've never tried it, so I cannot speak with certainty to the outcome)



CloudFlare actually does do SSL for your domain without warnings or SNI. They essentially have a large pool of shared certificates with lots of SANs, so your domain ends up as a SAN on one of their shared certificates with half a dozen other CloudFlare customers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: