#ERR_SSL_VERSION_OR_CIPHER_MISMATCH Chrome
36 messages · Page 1 of 1 (latest)
?pings
Please do not ping community members for non-moderation reasons. Doing so will not solve your issue faster and will make people less likely to want to help you.
Direct connection is work
And we need much more info
Domain? What are your SSL settings in CF? does your origin have a cert? What are you trying to achieve?
mjj.ee A @1.1.1.1 +noall +answer
NAME | TTL | DATA
--------------------------+------+----------------------
mjj.ee | 600s | mjj.ee.cdn.cloudflare
| | .net.
mjj.ee.cdn.cloudflare.net | 300s | 104.21.94.53
mjj.ee.cdn.cloudflare.net | 300s | 172.67.220.37
what
It had been working normally, but the domain name expired in August and I forgot to renew it. After renewing it again, there was a problem with the certificate.
It looks like the issue is about the connection between cloudflare and your origin server.
Would you wanna check if you've opened port 443 on your origin server?
Possible investigation steps could be: https://developers.cloudflare.com/ssl/troubleshooting/version-cipher-mismatch/#decision-tree
why are you doing a subdomain setup
you have an apex CNAME record
that is a violation of the DNS spec
Yes it's open
answer my questions
you have an apex CNAME record
I don't quite understand
why are you doing a subdomain setup
Which record are you referring to?
go to your overview on cloudflare
and send a screenshot of that
how do you have a partial setup on a free plan
anyway, go to SSL/TLS and check if universal SSL is enabled
where is the first screenshot from?
Is this the record?
Well I think "Edge Certificates" should be above this screenshot
YES
Oh right, sorry I missed your first screenshot.
To me it's a bit weird because you have subdomains there but not something like example.com and *.example.com
I discovered that I didn't add the _acme-challenge record, I'm trying to add
So you may have found that you don't have any SSL issue with your subdomains like chat.mjj.ee
If I understand it correctly, it could be the cert for your chat subdomain. You would either need a separate cert for each subdomain, or you need a wildcard cert.
no

<@&797524744156086293> help me
You’ve already been told to not ping roles