SSL_ERROR_NO_CYPHER_OVERLAP
Root domain, not on a subdoain, bayon.et seems to return this error (https).
I've made sure its cloudflare, webserver is fine, VPS is fine, its definitly cloudflare causing this problem.
On Edge Certificates, "Status Timed Out Validations (TXT)"
SSL is on FULL as I am using my own cert on my VPS (done with certbot)
12 Replies
Your domain is pointing at norah.ns.cloudflare.com and
duke.ns.cloudflare.com
, but they're both responding saying they are not authoritive/setup for your domain. So Cloudflare can't issue the ssl cert because it doesn't have control over the dns
Under DNS -> Records, if you scroll down to Cloudflare Nameservers
, it should tell you the ones it wants you to use
CF recently changed it so if you try to preset your account's default/preferred nameservers at your registrar before adding the domain to Cloudflare, Cloudflare will pick two different ones to protect against domain hijacking. Perhaps what you hit
SSL is on FULL as I am using my own cert on my VPS (done with certbot)Also don't use Full, it's insecure. Anyone could MITM the connection and serve any certificate and it would accept it. Under SSL/TLS -> Origin Server you can get an Origin Certficate, issued by Cloudflare which lasts up to 15 years and works with Full (Strict) Once you correct the nameservers issue you'll want to disable universal ssl for ~5 minutes and re-enable so it tries again
Yeah i ended up just removing it from cloudflare and then putting it back on cloudflare to reobtain the certs, weird that even after trying the 5 min disable/enable it didnt fix it
@Chaika
still having the same issue.
new discord account btw*
@Community Champion
Pleasn
also why is there no easy way to actually contact cloudflare support? seems i just get stuck with being sent to their community forum and their AI
?pings
Please do not ping community members for non-moderation reasons. Doing so will not solve your issue faster and will make people less likely to want to help you.
oj
Hehe.. what @Unsmart | Tech debt said 🙂
well idk how else to get any responce, im kinda down a very expensive domain and im on the clock yano times tickin
the rizzard needs help gang