https://discord.cloudflare.com logo
Join Discord
Powered by
# general-discussions
  • c

    Chaika

    04/06/2023, 1:13 AM
    Yea, makes sense. They've probably got some of the DNS scanning stuff I was mentioning. Perhaps what I saw above is merely propagation delay (of them disabling serving the cert since DNS changed) and not a misconfiguration/bug, the behavior of serving a valid cert of a different customer is odd though
  • r

    Ryder Cragie

    04/06/2023, 1:14 AM
    Thanks
  • r

    Ryder Cragie

    04/06/2023, 1:19 AM
    The .ml domain isn't in the certificate anymore. Scan again.
  • c

    Chaika

    04/06/2023, 1:22 AM
    They did something on their end? I still just got it once: * ALPN: server accepted h2 * Server certificate: * subject: CN=152i.ml * start date: Feb 23 06:26:59 2023 GMT * expire date: May 24 06:26:58 2023 GMT * subjectAltName does not match forum.rydercragie.com * SSL: no alternative certificate subject name matches target host name 'forum.rydercragie.com'
  • c

    Chaika

    04/06/2023, 1:23 AM
    tbh it's too fast to be something like DNS Scanning, it shouldn't instantly error out the second you turn on proxy. I assume they have some other weird behavior or something else going on, not sure but I suppose the end result is the same eitherway
  • r

    Ryder Cragie

    04/06/2023, 1:24 AM
    I did a ctrl + f on here and typed ".ml". No matches. It was listed on the below site before, so yes they must have changed something (automated I imagine). https://www.sslshopper.com/ssl-checker.html#hostname=forum.rydercragie.com
  • r

    Ryder Cragie

    04/06/2023, 1:24 AM
    Don't know how to use curl.
  • c

    Chaika

    04/06/2023, 1:25 AM
    It's not on 100% of requests, I get it on every 10th or so request now, before it seemed to occur more
  • r

    Ryder Cragie

    04/06/2023, 1:25 AM
    Interesting
  • r

    Ryder Cragie

    04/06/2023, 1:25 AM
    Though we are going off topic as it's now unrelated to cloudflare.
  • c

    Chaika

    04/06/2023, 1:26 AM
    If I refresh your website enough, I get the same error on it: (If you want to test this, make sure you hard refresh shift+f5)
  • c

    Chaika

    04/06/2023, 1:27 AM
    Yea true, off topic now. This is the same thing that stops Full Strict from working though, Full would accept a cert from 152i.ml, Full Strict wouldn't.
  • r

    Ryder Cragie

    04/06/2023, 1:27 AM
    Is HSTS affecting it do you think?
  • c

    Chaika

    04/06/2023, 1:27 AM
    No
  • r

    Ryder Cragie

    04/06/2023, 1:27 AM
    I can't imagine that being the case.
  • c

    Chaika

    04/06/2023, 1:28 AM
    All HSTS does is force all connections to https
  • c

    Chaika

    04/06/2023, 1:28 AM
    This is origin server randomly serving the wrong certificate type issue
  • r

    Ryder Cragie

    04/06/2023, 1:28 AM
    I'll mention it to them.
  • c

    Chaika

    04/06/2023, 1:31 AM
    I would specifically mention that domain (152i.ml) and include a screenshot. There's no valid reason I can think of to serve another customer's cert outside of some error on their end
  • r

    Ryder Cragie

    04/06/2023, 1:31 AM
    I'd still say that's secure though.
  • r

    Ryder Cragie

    04/06/2023, 1:31 AM
    In terms of threats.
  • l

    Luix2

    04/06/2023, 1:40 AM
  • l

    Luix2

    04/06/2023, 1:41 AM
    please ignore first picture , i have cloud and protection which is the wildcard for all servers under the domain that is giving a OTP for emails
  • l

    Luix2

    04/06/2023, 1:41 AM
    Its throwing this error after i set these rules
  • m

    marais

    04/06/2023, 1:42 AM
    that's interesting. seeing as no egress charges. and the font rsms is storing is 300KB. meaning cache 10TB is fine, because cache reserve has the 300kb file in it?
  • l

    Luix2

    04/06/2023, 1:42 AM
    lool
  • l

    Luix2

    04/06/2023, 1:42 AM
    just close your eyes nyaan
  • l

    Luix2

    04/06/2023, 1:43 AM
    nvm it workie now
  • l

    Luix2

    04/06/2023, 1:43 AM
    i guess it had to do some changes on the backend
  • l

    Luix2

    04/06/2023, 1:43 AM
1...395539563957...4267Latest