https://discord.cloudflare.com logo
Join Discord
Powered by
# workers-discussions
  • w

    Walshy | Pages

    05/05/2023, 11:05 PM
    being in ct logs isn't really a big deal, a bot would probably find the domain anyway pretty quick. You can't really do anything on a domain without it being known
  • u

    Unsmart | Tech debt

    05/05/2023, 11:06 PM
    Yeah easier... and what if a user has a cert they made for other services which then gets tied to it and they dont know and delete the cert... boom broken worker. Creating it specifically for the worker means its obvious what its for.
  • w

    Walshy | Pages

    05/05/2023, 11:06 PM
    yeah there's a lot of issues if we tried to use an existing cert haha
  • n

    Nyyrikki

    05/05/2023, 11:06 PM
    Walshy yes I know about CT logs not being such a big deal and that's its mostly of a security by obscurity reasoning
  • n

    Nyyrikki

    05/05/2023, 11:08 PM
    It's just that I am an Ent customer and I want to avoid publishing all my endpoints names in CT logs because I have people a bit too much interested in what we do and I get a lot of beg bounties just because of this
  • n

    Nyyrikki

    05/05/2023, 11:08 PM
    Less in CT logs = less headaches for me
  • n

    Nyyrikki

    05/05/2023, 11:08 PM
    But thanks for letting me know about the behaviour I will handle it another way then, cheers
  • w

    Walshy | Pages

    05/05/2023, 11:09 PM
    yeah i'd recommend just using routes then
  • c

    Chaika

    05/05/2023, 11:18 PM
    You can delete them without any issues. It'll show the cert as Inactive in the custom domains tab, but it should continue working with no issue. The docs recommend you delete the original cert if you want to replace it/use a different one
  • c

    Chaika

    05/05/2023, 11:20 PM
    If you delete the cert fast enough, you can usually snipe it before it issues. Custom Domains are still easier to use then routes, so I just do that. Not something to rely on of course if you absolutely need one not to be issued.
  • n

    Nyyrikki

    05/05/2023, 11:24 PM
    Thanks Chaika, I deleted the extra cert in ACM but the custom domain disappeared in the Worker, or maybe it was just a UI fluke on my side. Anyways I think i will stay on routes as Walshy suggested, needs a bit more work but at least doesn't publish certs
  • n

    Nyyrikki

    05/05/2023, 11:24 PM
    I just assumed that it worked like custom domains of Cloudflare Pages (that doesn't do this) but at least now i know :)
  • c

    Chaika

    05/05/2023, 11:25 PM
    That's strange, in the docs of Custom Domains they tell you to delete the cert if you want to replace it, so it should be 100% supported and I haven't had any issues with it.
  • c

    Chaika

    05/05/2023, 11:26 PM
    Pages should always issue a cert as well, and you can't delete that one, unless there's some way I don't know of to create a pages custom domain without one (It's not visible in your edge certs either, but it's visible in CT logs of course)
  • d

    dave

    05/05/2023, 11:50 PM
    you can just listen on a wildcard for the worker
  • d

    dave

    05/06/2023, 12:01 AM
    @Erisa | Support Engineer see ^
  • d

    dave

    05/06/2023, 12:01 AM
    I take no blame ;P
  • e

    Erisa | Support Engineer

    05/06/2023, 12:01 AM
    (I replied in the thread as well)
  • e

    Erisa | Support Engineer

    05/06/2023, 12:01 AM
    I'm just curious whether you're actually seeing this, or what led you to believe it worked the way you described rather than what the docs say 🤔
  • d

    dave

    05/06/2023, 12:02 AM
    probably 18 hours of working yesterday and being a bit confused.
  • e

    Erisa | Support Engineer

    05/06/2023, 12:02 AM
    Oh
  • d

    dave

    05/06/2023, 12:04 AM
    hang on
  • d

    dave

    05/06/2023, 12:05 AM
    How do I actually verify that
    CF-Worker
    is not being added by a CF Warp customer?
  • d

    dave

    05/06/2023, 12:05 AM
    since they use the same IP ranges
  • e

    Erisa | Support Engineer

    05/06/2023, 12:05 AM
    cf- headers cant be spoofed
  • d

    dave

    05/06/2023, 12:05 AM
    but this would be through SSL
  • e

    Erisa | Support Engineer

    05/06/2023, 12:05 AM
    Oh wait
  • e

    Erisa | Support Engineer

    05/06/2023, 12:05 AM
    Was thinking of ingress, not egress
  • e

    Erisa | Support Engineer

    05/06/2023, 12:05 AM
    in this case,
  • e

    Erisa | Support Engineer

    05/06/2023, 12:06 AM
    WARP does not use any of the IPs listed at
1...244024412442...2509Latest