#ERR_SSL_VERSION_OR_CIPHER_MISMATCH - Edge Certificate pending validation

1 messages · Page 1 of 1 (latest)

tiny whale
#

You possibly need to disable or reconfigure DNSSEC on both sides

alpine narwhal
#

Alright, I just configured DNSSEC on Porkbun. I copied values from Cloudfare

#

How long should I wait? I disabled and enabled the Uniersal SSL once now

#

Okay the dashboard says

DNSSEC is pending while we wait for the DS to be added to your registrar. This usually takes ten minutes, but can take up to an hour.
I'll keep posted

alpine narwhal
#

Doesn't help.

#

It's still pending validation

#

Should I wait longer?

#

This is my current DNS records

tiny whale
#

the zone is in Active state right?

alpine narwhal
#

Meaning the domain? Yes

#

It's on Porkbun.

alpine narwhal
#

I modified all the settings. Nothing is working. Sad. 😢

alpine narwhal
#

So I repeated the process again

  1. Removed the cloudflare
  2. Added the domain again
  3. Updated the nameserver

Again same issue

storm vapor
alpine narwhal
#

Sadly, I don't have any wildcard record

oblique valveBOT
#
DNS over Discord: A records

blah.blah.softinttech.org A @1.1.1.3 +noall +answer

NAME                      | TTL  | DATA          
--------------------------+------+---------------
blah.blah.softinttech.org | 300s | 172.67.137.140
blah.blah.softinttech.org | 300s | 104.21.62.168 
storm vapor
#

you've got one somewhere somehow

#

at the bottom of the dns records page, what does it say your Cloudflare nameservers are?

alpine narwhal
storm vapor
# alpine narwhal This.

Cool, so it looks like it just doesn't care about your dns settings at all. Your domain is spelled right, right? supposed to be softinttech.org misspelled w/ two t's and not softintech.org?

alpine narwhal
#

two t is correct

#

soft int tech .org

storm vapor
#

Thanks for confirming, this is something that would have to be escalated to support then, looks like there's a ghost dns zone overriding/it just doesn't care about yours and neither of us see anything obviously wrong with your setup. Trying to see the best way to go about that

alpine narwhal
#

Strangely the API also doesn't return the ghost record.

storm vapor
#

this was escalated and they reached out on the community thread asking you to make a registrar ticket to be escalated as they think it's related to that (and also a record on your apex as another thing to try)

alpine narwhal
#

Thank you. Case ID: 01227438

#

and how to setup the apex?

alpine narwhal
#

So they just closed the ticket, Because I'm on a free plan

oblique valveBOT
#
DNS over Discord: A records

softinttech.org A @1.1.1.1 +noall +answer

NAME            | TTL  | DATA          
----------------+------+---------------
softinttech.org | 300s | 172.67.137.140
softinttech.org | 300s | 104.21.62.168 
old night
#

@alpine narwhal do you have an ssl certificate at the endpoint?

alpine narwhal
old night
# alpine narwhal Yes. I have let's encrypt

i would double check and make sure it's actually issued and current. I had this error before and based on my research it was due to the endpoint ssl cert not being issued yet.

alpine narwhal
#

Thanks David. Let me double check

alpine narwhal
#

Hi @old night Yes. I removed the cloudflare and double checked. The subdomains has own SSL certificates.
The moment I turn ON cloudflare, the error comes back again

old night
#

Ssl is set to full (strict)?

tiny whale
#

the ssl setting won't matter for this error (though it should always be full strict regardless), the error happens because there's no edge certificate issued and there not being one issued is a cloudflare issue which is why chaika escalated it. i can only assume the ticket being closed was a mistake and I've already mentioned that on the escalation for someone to correct

old night
#

Oh. I was mistaken. I couldn't /didn't see the whole error massage. Thanks for clarifying

tiny whale
#

no worries

alpine narwhal
#

Thank you

oblique valveBOT
#
DNS over Discord: A records

softinttech.org A @1.1.1.1 +noall +answer

NAME            | TTL  | DATA          
----------------+------+---------------
softinttech.org | 300s | 104.21.62.168 
softinttech.org | 300s | 172.67.137.140
#
DNS over Discord: A records

db.softinttech.org A @1.1.1.1 +noall +answer

NAME               | TTL  | DATA          
-------------------+------+---------------
db.softinttech.org | 300s | 104.21.62.168 
db.softinttech.org | 300s | 172.67.137.140
alpine narwhal
#

Case ID: 01227438

Cloudflare support is super slow. Things I did so far

  • Moved the domain name back to porkbun
  • Paused and Resume cloudflare
  • Turned of Proxy for 24 hours and enabled it
  • Disabled DNSEC for 24 hours and enabled it
  • Disabled Universal Certificate for 24 hours and enabled it
  • Even if the orange cloud is off, DNS checkers not showing the IP (Meaning Cloudflare is not resolving the DNS too)

Can I upgrade to Pro plan for better support? I'm losing business due to this issue

spark jackal