DNS records "this hostname is not covered by a certificate"

Still have not solved this... causing a lot of pain. We do have universal certificate active, and we do have the correct CAA records set up (tangia.co):
0 issue "comodoca.com"
0 issue "digicert.com; cansignhttpexchanges=yes"
0 issue "pki.goog; cansignhttpexchanges=yes"
0 issuewild "comodoca.com"
0 issuewild "digicert.com; cansignhttpexchanges=yes"
0 issuewild "letsencrypt.org"
0 issuewild "pki.goog; cansignhttpexchanges=yes"
0 issue "letsencrypt.org"
0 issue "globalsign.com"
0 issue "amazon.com"
0 issue "amazontrust.com"
0 issue "awstrust.com"
0 issue "amazonaws.com"
0 issue "comodoca.com"
0 issue "digicert.com; cansignhttpexchanges=yes"
0 issue "pki.goog; cansignhttpexchanges=yes"
0 issuewild "comodoca.com"
0 issuewild "digicert.com; cansignhttpexchanges=yes"
0 issuewild "letsencrypt.org"
0 issuewild "pki.goog; cansignhttpexchanges=yes"
0 issue "letsencrypt.org"
0 issue "globalsign.com"
0 issue "amazon.com"
0 issue "amazontrust.com"
0 issue "awstrust.com"
0 issue "amazonaws.com"
18 Replies
Cyb3r-Jak3
Cyb3r-Jak3•2y ago
It is only a UI issue or does it show there isn't a certificate if you visit one of the domains?
DanTheGoodman
DanTheGoodmanOP•2y ago
@Cyb3r-Jok3 cert issue
DanTheGoodman
DanTheGoodmanOP•2y ago
I also tried removing the caa records about 20 min ago, no change
Cyb3r-Jak3
Cyb3r-Jak3•2y ago
Does it show you having a valid universal certificate here: https://dash.cloudflare.com/?to=/:account/:zone/ssl-tls/edge-certificates
DanTheGoodman
DanTheGoodmanOP•2y ago
Yes @Cyb3r-Jok3
DanTheGoodman
DanTheGoodmanOP•2y ago
This was a problem we had before and I added extra records to CAA which fixed it, but it seems to be back huh, seems to only be an issue with the A record, https://leaderboard-frontend.cf.tangia.co/ works fine
Cyb3r-Jak3
Cyb3r-Jak3•2y ago
It is me or is there no universal SSL certificate there
DanTheGoodman
DanTheGoodmanOP•2y ago
maybe I don't know what it looks like, but I do see that there is a disable button
Cyb3r-Jak3
Cyb3r-Jak3•2y ago
The type would be universal. Try disabling for 5 minutes then re-enable to see if that gets the certifcate reissued
DanTheGoodman
DanTheGoodmanOP•2y ago
wouldn't that last one be uni? ok
DanTheGoodman
DanTheGoodmanOP•2y ago
DanTheGoodman
DanTheGoodmanOP•2y ago
welp... assuming it validates, I think that might have been it cert isn't ready yet, but the UI warnings went away @Cyb3r-Jok3 do you know how long this should take? all done! thanks for the help 😄 although I am getting 521's on the icedb subdomain... lol
Cyb3r-Jak3
Cyb3r-Jak3•2y ago
Does it work if you unproxy?
DanTheGoodman
DanTheGoodmanOP•2y ago
I think the server is actually borked right now, docker andport 80 stuff
Cyb3r-Jak3
Cyb3r-Jak3•2y ago
Always fun lol
DanTheGoodman
DanTheGoodmanOP•2y ago
Iirc workers can't call non-standard ports so I got to get this working lol works fine on 8090 working now 😄
Cyb3r-Jak3
Cyb3r-Jak3•2y ago
🎉
DanTheGoodman
DanTheGoodmanOP•2y ago
appreciate the help!
Want results from more Discord servers?
Add your server