

For example, the vast majority of mobile applications use embedded certificates. ESNI and ECH handshake encryption Incompatible certificatesĪpplications that use embedded certificates and mTLS authentication do not trust the Cloudflare certificate.Gateway does not support TLS decryption for applications which use: (Optional) Select Enable only cipher suites and TLS versions compliant with FIPS 140-2.In Zero Trust External link icon Open external link, go to Settings > Network.When you enable TLS decryption, Gateway will decrypt all traffic sent over HTTPS, apply your HTTP policies, and then re-encrypt the request with a user-side certificate. Cloudflare Gateway can perform SSL/TLS decryption External link icon Open external link in order to inspect HTTPS traffic for malware and other security risks.
