Cloudflare AKE Reduces Origin HelloRetryRequests to 3.7%
Cloudflare has announced a new feature called Automatic Key Exchange for Origins, designed to streamline the process of securing traffic between its edge network and origin servers. The update automatically negotiates TLS keys, eliminating the need for site operators to manually manage certificates or configure complex TLS settings on their origin infrastructure.
The mechanism leverages Cloudflare’s own TLS certificates and integrates with the platform’s existing security stack. By handling key rotation and renewal behind the scenes, the feature reduces operational overhead and mitigates common misconfiguration risks. It is compatible with both HTTP/2 and HTTP/3 traffic, ensuring that performance gains from newer protocols are fully realized without additional setup from the user.
With Automatic Key Exchange now available, Cloudflare aims to lower the barrier to secure deployment for its customers. The feature is rolled out as part of the broader effort to simplify TLS management and improve end‑to‑end encryption across the network. Site administrators can enable the functionality through the Cloudflare dashboard, after which the system takes care of the rest.