Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. AdGuard Home
  3. AdGuard Home Wildcard aliases

AdGuard Home Wildcard aliases

Scheduled Pinned Locked Moved Solved AdGuard Home
porkbunwildcard
56 Posts 6 Posters 10.0k Views 6 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • girishG girish

    @lukas Yup, so in next release, it should work 🤞 You have to switch to some other provider for something immediate (like today).

    L Offline
    L Offline
    lukas
    wrote on last edited by
    #32

    @girish ok, then I will wait for next release. Will it come today? 🙂

    1 Reply Last reply
    0
    • girishG girish

      @lukas Yeah, so they never got back 😕 I even sent them a reminder. Please point them to this thread (if you are a customer). I sent mails from girish@cloudron.io

      Unfortunately, one cannot create a wildcard certificate from the Wildcard Domain. This is because Let's Encrypt requires you to set values in the DNS to get a wildcard cert. With a wildcard provider, Cloudron has no way to program the DNS. Only fix right now is to switch to some other programmable DNS provider. Sorry...

      L Offline
      L Offline
      lukas
      wrote on last edited by
      #33

      @girish said in AdGuard Home Wildcard aliases:

      Yeah, so they never got back I even sent them a reminder. Please point them to this thread (if you are a customer). I sent mails from girish@cloudron.io

      you got maybe any ticket number? I will contact them now

      girishG 1 Reply Last reply
      0
      • L lukas

        @girish said in AdGuard Home Wildcard aliases:

        Yeah, so they never got back I even sent them a reminder. Please point them to this thread (if you are a customer). I sent mails from girish@cloudron.io

        you got maybe any ticket number? I will contact them now

        girishG Do not disturb
        girishG Do not disturb
        girish
        Staff
        wrote on last edited by
        #34

        @lukas they didn't give me one.

        L 1 Reply Last reply
        1
        • girishG girish

          @lukas they didn't give me one.

          L Offline
          L Offline
          lukas
          wrote on last edited by
          #35

          @girish update to latest Cloudron Version, bunny.net integration is working fine (thanks for this), but DoT on my Android Phone is still not working, in AdGuard Home Log I see:

          May 02 10:35:57 2023/05/02 08:35:57.599729 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
          May 02 10:35:57 2023/05/02 08:35:57.907614 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
          May 02 10:35:57 2023/05/02 08:35:57.914408 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
          

          What is wrong? I use <clientname>.adguard.mydomain.TLD and I added an Alias (*.adgaurd) to AdGuard Home.

          What is wrong?

          Thank you and Regards,
          Lukas

          girishG 1 Reply Last reply
          0
          • L lukas

            @girish update to latest Cloudron Version, bunny.net integration is working fine (thanks for this), but DoT on my Android Phone is still not working, in AdGuard Home Log I see:

            May 02 10:35:57 2023/05/02 08:35:57.599729 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
            May 02 10:35:57 2023/05/02 08:35:57.907614 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
            May 02 10:35:57 2023/05/02 08:35:57.914408 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
            

            What is wrong? I use <clientname>.adguard.mydomain.TLD and I added an Alias (*.adgaurd) to AdGuard Home.

            What is wrong?

            Thank you and Regards,
            Lukas

            girishG Do not disturb
            girishG Do not disturb
            girish
            Staff
            wrote on last edited by
            #36

            @lukas If you go to Location view and click Save (without making any changes), does that help the situation ? That should maybe (re)trigger getting the cert.

            L 1 Reply Last reply
            0
            • girishG girish

              @lukas If you go to Location view and click Save (without making any changes), does that help the situation ? That should maybe (re)trigger getting the cert.

              L Offline
              L Offline
              lukas
              wrote on last edited by
              #37

              @girish did not help. This looks also not fine:

              bdca3c66-576e-4891-b1b3-9026d9d2be43-image.png

              Certificate chain is invalid

              girishG 1 Reply Last reply
              0
              • L lukas

                @girish did not help. This looks also not fine:

                bdca3c66-576e-4891-b1b3-9026d9d2be43-image.png

                Certificate chain is invalid

                girishG Do not disturb
                girishG Do not disturb
                girish
                Staff
                wrote on last edited by
                #38

                @lukas can you check the output of openssl x509 -text -in /etc/certs/_.adguard.domain.cert in the web terminal of adguard ? Does it seem like a valid Let's Encrypt certificate?

                L 1 Reply Last reply
                0
                • girishG girish

                  @lukas can you check the output of openssl x509 -text -in /etc/certs/_.adguard.domain.cert in the web terminal of adguard ? Does it seem like a valid Let's Encrypt certificate?

                  L Offline
                  L Offline
                  lukas
                  wrote on last edited by
                  #39

                  @girish I see an output. Which part do you need from this ouput?

                  girishG 1 Reply Last reply
                  0
                  • L lukas

                    @girish I see an output. Which part do you need from this ouput?

                    girishG Do not disturb
                    girishG Do not disturb
                    girish
                    Staff
                    wrote on last edited by
                    #40

                    @lukas The first few lines should give us the issuer and expiry like this:

                    Certificate:
                        Data:
                            Version: 3 (0x2)
                            Serial Number:
                                04:1d:71:e7:48:c7:d3:80:02:ac:c1:ac:5b:79:e5:3f:3e:4e
                            Signature Algorithm: sha256WithRSAEncryption
                            Issuer: C = US, O = Let's Encrypt, CN = R3
                            Validity
                                Not Before: Apr 15 02:11:00 2023 GMT
                                Not After : Jul 14 02:10:59 2023 GMT
                    

                    Then later down, you should also see the SAN section:

                                X509v3 Subject Alternative Name: 
                                    DNS:*.girish.in
                    

                    Ideally, there should the wildcard and non-wildcard DNS listed above in your case.

                    L 1 Reply Last reply
                    0
                    • girishG girish

                      @lukas The first few lines should give us the issuer and expiry like this:

                      Certificate:
                          Data:
                              Version: 3 (0x2)
                              Serial Number:
                                  04:1d:71:e7:48:c7:d3:80:02:ac:c1:ac:5b:79:e5:3f:3e:4e
                              Signature Algorithm: sha256WithRSAEncryption
                              Issuer: C = US, O = Let's Encrypt, CN = R3
                              Validity
                                  Not Before: Apr 15 02:11:00 2023 GMT
                                  Not After : Jul 14 02:10:59 2023 GMT
                      

                      Then later down, you should also see the SAN section:

                                  X509v3 Subject Alternative Name: 
                                      DNS:*.girish.in
                      

                      Ideally, there should the wildcard and non-wildcard DNS listed above in your case.

                      L Offline
                      L Offline
                      lukas
                      wrote on last edited by lukas
                      #41

                      @girish

                      Certificate:
                          Data:
                              Version: 3 (0x2)
                              Serial Number:
                                  36:5d:97:51:3d:9f:45:89:58:45:67:c2:82:a6:83:3f:6d:50:69:0b
                              Signature Algorithm: sha256WithRSAEncryption
                              Issuer: CN = *.mydomain.cloud
                              Validity
                                  Not Before: Apr  2 14:06:15 2023 GMT
                                  Not After : Jun 10 14:06:15 2025 GMT
                      

                      and

                      			        X509v3 extensions:
                                  X509v3 Subject Alternative Name: 
                                      DNS:mydomain.cloud, DNS:*.mydomain.cloud
                      
                      girishG 1 Reply Last reply
                      0
                      • L lukas

                        @girish

                        Certificate:
                            Data:
                                Version: 3 (0x2)
                                Serial Number:
                                    36:5d:97:51:3d:9f:45:89:58:45:67:c2:82:a6:83:3f:6d:50:69:0b
                                Signature Algorithm: sha256WithRSAEncryption
                                Issuer: CN = *.mydomain.cloud
                                Validity
                                    Not Before: Apr  2 14:06:15 2023 GMT
                                    Not After : Jun 10 14:06:15 2025 GMT
                        

                        and

                        			        X509v3 extensions:
                                    X509v3 Subject Alternative Name: 
                                        DNS:mydomain.cloud, DNS:*.mydomain.cloud
                        
                        girishG Do not disturb
                        girishG Do not disturb
                        girish
                        Staff
                        wrote on last edited by
                        #42

                        @lukas It's not getting the new certs for some reason - it's using the self-signed cert. If you go to Domains -> Renew all certs. Can you check the logs when it's renewing? Do you see any errors?

                        L 1 Reply Last reply
                        0
                        • girishG girish

                          @lukas It's not getting the new certs for some reason - it's using the self-signed cert. If you go to Domains -> Renew all certs. Can you check the logs when it's renewing? Do you see any errors?

                          L Offline
                          L Offline
                          lukas
                          wrote on last edited by
                          #43

                          @girish I sent you the log-file via E-Mail

                          girishG 1 Reply Last reply
                          0
                          • L lukas

                            @girish I sent you the log-file via E-Mail

                            girishG Do not disturb
                            girishG Do not disturb
                            girish
                            Staff
                            wrote on last edited by
                            #44

                            @lukas From the logs, it seems the domain is not using Wildcard certs at all. If you go to Domains -> Edit -> Advanced. What is the certificate provider ? I suspect it's not wildcard . Can you change it and try to renew certs again?

                            I guess the reason is because you went from maybe Wildcard DNS to Programmatic DNS. In wildcard DNS, wildcard cert is not possible. But this is indeed a workflow/ui thing, that we have to consider in the future.

                            girishG 1 Reply Last reply
                            0
                            • girishG girish

                              @lukas From the logs, it seems the domain is not using Wildcard certs at all. If you go to Domains -> Edit -> Advanced. What is the certificate provider ? I suspect it's not wildcard . Can you change it and try to renew certs again?

                              I guess the reason is because you went from maybe Wildcard DNS to Programmatic DNS. In wildcard DNS, wildcard cert is not possible. But this is indeed a workflow/ui thing, that we have to consider in the future.

                              girishG Do not disturb
                              girishG Do not disturb
                              girish
                              Staff
                              wrote on last edited by
                              #45

                              The certificate provider should be Let's Encrypt Prod - Wildcard

                              L 2 Replies Last reply
                              0
                              • girishG girish

                                The certificate provider should be Let's Encrypt Prod - Wildcard

                                L Offline
                                L Offline
                                lukas
                                wrote on last edited by
                                #46

                                @girish this is set and I haven't change it. Just today changed the DNS Provider from Wildcard to Bunny

                                57f1d68f-ae04-4dab-9c26-02744c411ad3-image.png

                                1 Reply Last reply
                                0
                                • girishG girish

                                  The certificate provider should be Let's Encrypt Prod - Wildcard

                                  L Offline
                                  L Offline
                                  lukas
                                  wrote on last edited by
                                  #47

                                  @girish so which steps do I need to go, to get this resolved?

                                  Btw. I see there some "non-used" SSL certificates, is there any kind of "housekeeping" ?

                                  girishG 1 Reply Last reply
                                  0
                                  • L lukas

                                    @girish so which steps do I need to go, to get this resolved?

                                    Btw. I see there some "non-used" SSL certificates, is there any kind of "housekeeping" ?

                                    girishG Do not disturb
                                    girishG Do not disturb
                                    girish
                                    Staff
                                    wrote on last edited by
                                    #48

                                    @lukas I am a bit lost at this point. Are you able contact me at support@cloudron.io , so I can debug your instance?

                                    L 1 Reply Last reply
                                    0
                                    • girishG girish

                                      @lukas I am a bit lost at this point. Are you able contact me at support@cloudron.io , so I can debug your instance?

                                      L Offline
                                      L Offline
                                      lukas
                                      wrote on last edited by
                                      #49

                                      @girish sure, I give you access. I open a Ticket via Cloudron

                                      girishG 1 Reply Last reply
                                      1
                                      • L lukas

                                        @girish sure, I give you access. I open a Ticket via Cloudron

                                        girishG Do not disturb
                                        girishG Do not disturb
                                        girish
                                        Staff
                                        wrote on last edited by
                                        #50

                                        @lukas thanks! As a heads up, I will only be able to debug a bit later today.

                                        L 1 Reply Last reply
                                        0
                                        • girishG girish

                                          @lukas thanks! As a heads up, I will only be able to debug a bit later today.

                                          L Offline
                                          L Offline
                                          lukas
                                          wrote on last edited by
                                          #51

                                          @girish said in AdGuard Home Wildcard aliases:

                                          @lukas thanks! As a heads up, I will only be able to debug a bit later today.

                                          all right, thank you very much for your amazing support!

                                          girishG 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Bookmarks
                                          • Search