logoalt Hacker News

keehunlast Sunday at 8:30 PM2 repliesview on HN

TLS termination is neither required nor enabled by default, right?


Replies

crimsonnoodle58last Sunday at 8:34 PM

Correct. We run it without it and just use the DNS filtering aspect.

show 1 reply
jchwlast Sunday at 9:34 PM

For tunnels many of the features basically have to work this way, so I'd be surprised if you could avoid it. It's also impossible to avoid if you use normal Cloudflare "protected" DNS entries. You can use Cloudflare as just a DNS server but it's not the default, by default it will proxy everything through Cloudflare, since that's kind of the point. You can't cache HTTP requests you can't see.