ERR_SSL_VERSION_OR_CIPHER_MISMATCH - Edge Certificate pending validation

What is the name of the domain? softinttech.org What is the error message? ERR_SSL_VERSION_OR_CIPHER_MISMATCH 1 What is the issue you’re encountering ERR_SSL_VERSION_OR_CIPHER_MISMATCH 1 What steps have you taken to resolve the issue? Removed and added the domain again to Cloudflare, still the Edge certificate is showing pending validation. I recently moved my domain from Cloudflare to Porkbun. After this, I’m facing this issue. But the NS is set properly in porkbub. I do have let’s encrypt in server. What is the current SSL/TLS setting? Full (strict) https://community.cloudflare.com/t/err-ssl-version-or-cipher-mismatch-edge-certificate-pending-validation/722721/1
38 Replies
Erisa
Erisa2w ago
You possibly need to disable or reconfigure DNSSEC on both sides
Naveen MC
Naveen MC2w ago
Alright, I just configured DNSSEC on Porkbun. I copied values from Cloudfare
Naveen MC
Naveen MC2w ago
How long should I wait? I disabled and enabled the Uniersal SSL once now
No description
Naveen MC
Naveen MC2w ago
Okay the dashboard says
DNSSEC is pending while we wait for the DS to be added to your registrar. This usually takes ten minutes, but can take up to an hour.
I'll keep posted
Naveen MC
Naveen MC2w ago
Doesn't help.
No description
Naveen MC
Naveen MC2w ago
It's still pending validation
No description
Naveen MC
Naveen MC2w ago
Should I wait longer?
Naveen MC
Naveen MC2w ago
This is my current DNS records
No description
Erisa
Erisa2w ago
the zone is in Active state right?
Naveen MC
Naveen MC2w ago
Meaning the domain? Yes
Naveen MC
Naveen MC2w ago
It's on Porkbun.
No description
No description
Naveen MC
Naveen MC2w ago
I modified all the settings. Nothing is working. Sad. 😢 So I repeated the process again 1. Removed the cloudflare 2. Added the domain again 3. Updated the nameserver Again same issue
Naveen MC
Naveen MC2w ago
No description
Chaika
Chaika2w ago
Show your DNS Records in cf (bluring anything sensitive), it looks like you've got a wildcard cname or something
Naveen MC
Naveen MC2w ago
No description
Naveen MC
Naveen MC2w ago
Sadly, I don't have any wildcard record
1.1.1.1
1.1.1.12w ago
DNS over Discord: A records
blah.blah.softinttech.org A @1.1.1.3 +noall +answer
NAME | TTL | DATA
--------------------------+------+---------------
blah.blah.softinttech.org | 300s | 172.67.137.140
blah.blah.softinttech.org | 300s | 104.21.62.168
NAME | TTL | DATA
--------------------------+------+---------------
blah.blah.softinttech.org | 300s | 172.67.137.140
blah.blah.softinttech.org | 300s | 104.21.62.168
diggy diggy hole
Chaika
Chaika2w ago
you've got one somewhere somehow at the bottom of the dns records page, what does it say your Cloudflare nameservers are?
Naveen MC
Naveen MC2w ago
This.
No description
Chaika
Chaika2w ago
Cool, so it looks like it just doesn't care about your dns settings at all. Your domain is spelled right, right? supposed to be softinttech.org misspelled w/ two t's and not softintech.org?
Naveen MC
Naveen MC2w ago
two t is correct soft int tech .org
Chaika
Chaika2w ago
Thanks for confirming, this is something that would have to be escalated to support then, looks like there's a ghost dns zone overriding/it just doesn't care about yours and neither of us see anything obviously wrong with your setup. Trying to see the best way to go about that
Naveen MC
Naveen MC2w ago
Cool. Looking forward! Strangely the API also doesn't return the ghost record.
Chaika
Chaika2w ago
this was escalated and they reached out on the community thread asking you to make a registrar ticket to be escalated as they think it's related to that (and also a record on your apex as another thing to try)
Naveen MC
Naveen MC2w ago
Thank you. Case ID: 01227438 and how to setup the apex?
Naveen MC
Naveen MC2w ago
So they just closed the ticket, Because I'm on a free plan
No description
1.1.1.1
1.1.1.12w ago
DNS over Discord: A records
softinttech.org A @1.1.1.1 +noall +answer
NAME | TTL | DATA
----------------+------+---------------
softinttech.org | 300s | 172.67.137.140
softinttech.org | 300s | 104.21.62.168
NAME | TTL | DATA
----------------+------+---------------
softinttech.org | 300s | 172.67.137.140
softinttech.org | 300s | 104.21.62.168
diggy diggy hole
David Wang
David Wang2w ago
@Naveen MC do you have an ssl certificate at the endpoint?
Naveen MC
Naveen MC2w ago
Yes. I have let's encrypt
David Wang
David Wang2w ago
i would double check and make sure it's actually issued and current. I had this error before and based on my research it was due to the endpoint ssl cert not being issued yet.
Naveen MC
Naveen MC7d ago
Thanks David. Let me double check Hi @David Wang Yes. I removed the cloudflare and double checked. The subdomains has own SSL certificates. The moment I turn ON cloudflare, the error comes back again
David Wang
David Wang7d ago
Ssl is set to full (strict)?
Erisa
Erisa7d ago
the ssl setting won't matter for this error (though it should always be full strict regardless), the error happens because there's no edge certificate issued and there not being one issued is a cloudflare issue which is why chaika escalated it. i can only assume the ticket being closed was a mistake and I've already mentioned that on the escalation for someone to correct
David Wang
David Wang7d ago
Oh. I was mistaken. I couldn't /didn't see the whole error massage. Thanks for clarifying
Erisa
Erisa7d ago
no worries
Naveen MC
Naveen MC7d ago
Thank you
1.1.1.1
1.1.1.12d ago
DNS over Discord: A records
softinttech.org A @1.1.1.1 +noall +answer
NAME | TTL | DATA
----------------+------+---------------
softinttech.org | 300s | 104.21.62.168
softinttech.org | 300s | 172.67.137.140
NAME | TTL | DATA
----------------+------+---------------
softinttech.org | 300s | 104.21.62.168
softinttech.org | 300s | 172.67.137.140
diggy diggy hole
1.1.1.1
1.1.1.12d ago
DNS over Discord: A records
db.softinttech.org A @1.1.1.1 +noall +answer
NAME | TTL | DATA
-------------------+------+---------------
db.softinttech.org | 300s | 104.21.62.168
db.softinttech.org | 300s | 172.67.137.140
NAME | TTL | DATA
-------------------+------+---------------
db.softinttech.org | 300s | 104.21.62.168
db.softinttech.org | 300s | 172.67.137.140
diggy diggy hole
Want results from more Discord servers?
Add your server