Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Automated DNS (Cloudflare): *.domain.com added manually but subdomains visible. Normal?

Automated DNS (Cloudflare): *.domain.com added manually but subdomains visible. Normal?

Scheduled Pinned Locked Moved Discuss
5 Posts 2 Posters 1.5k Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • humptyH Offline
    humptyH Offline
    humpty
    wrote on last edited by
    #1

    I thought that if we used the programmable DNS, subdomains will be hidden from the certificate transparency log thing that is mentioned in the docs. I have Cloudflare API set up and it's been working fine.

    Today, I added an A record of *.domain.com and deleted all the A records of the sub.domain.com. Then, in the CR dashboard, I went to each app > location > save. I checked CF and all subdomains are back.

    Is this normal? If so, are the subdomains actually hidden? How can I check?

    girishG 1 Reply Last reply
    0
    • humptyH humpty

      I thought that if we used the programmable DNS, subdomains will be hidden from the certificate transparency log thing that is mentioned in the docs. I have Cloudflare API set up and it's been working fine.

      Today, I added an A record of *.domain.com and deleted all the A records of the sub.domain.com. Then, in the CR dashboard, I went to each app > location > save. I checked CF and all subdomains are back.

      Is this normal? If so, are the subdomains actually hidden? How can I check?

      girishG Offline
      girishG Offline
      girish
      Staff
      wrote on last edited by
      #2

      @humptydumpty DNS and Certificate Transparency are separate things.

      CT (via https://crt.sh/) is a public record of the certificates issued. When you search this for your domain, you will only see *.domain.com there. You won't see subdomains of individual apps.

      DNS entries are always individual. DNS has no API to query the subdomain list. You can only ask for a specific subdomain. So, even when we create individual entries in the DNS, for an outsider, there is no way to get the full entry list. You can only ask specifically for blog.domain.com and so on.

      humptyH 2 Replies Last reply
      1
      • girishG girish

        @humptydumpty DNS and Certificate Transparency are separate things.

        CT (via https://crt.sh/) is a public record of the certificates issued. When you search this for your domain, you will only see *.domain.com there. You won't see subdomains of individual apps.

        DNS entries are always individual. DNS has no API to query the subdomain list. You can only ask for a specific subdomain. So, even when we create individual entries in the DNS, for an outsider, there is no way to get the full entry list. You can only ask specifically for blog.domain.com and so on.

        humptyH Offline
        humptyH Offline
        humpty
        wrote on last edited by humpty
        #3

        @girish Thanks for the clarification. I did a DNS lookup and it's exactly as you said. However, I remember doing a search in the not-so-recent past that showed what domains were on my server IP (I forgot how I did that). I thought I could hide those. Thanks again.

        1 Reply Last reply
        0
        • girishG girish

          @humptydumpty DNS and Certificate Transparency are separate things.

          CT (via https://crt.sh/) is a public record of the certificates issued. When you search this for your domain, you will only see *.domain.com there. You won't see subdomains of individual apps.

          DNS entries are always individual. DNS has no API to query the subdomain list. You can only ask for a specific subdomain. So, even when we create individual entries in the DNS, for an outsider, there is no way to get the full entry list. You can only ask specifically for blog.domain.com and so on.

          humptyH Offline
          humptyH Offline
          humpty
          wrote on last edited by
          #4

          @girish It looks like crt.sh keeps a record of past (expired) certs. I'm seeing all the subs just by searching for the bare domain.

          girishG 1 Reply Last reply
          0
          • humptyH humpty

            @girish It looks like crt.sh keeps a record of past (expired) certs. I'm seeing all the subs just by searching for the bare domain.

            girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by
            #5

            @humptydumpty yes, correct. the log is forever. One thing is that Let's Encrypt itself only support wildcard certs in around 2016 or so. This meant that all LE domains before that are public in the log.

            1 Reply Last reply
            1

            Hello! It looks like you're interested in this conversation, but you don't have an account yet.

            Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

            With your input, this post could be even better 💗

            Register Login
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • Bookmarks
            • Search