Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Enable HSTS preload for this site and all subdomains problem

Enable HSTS preload for this site and all subdomains problem

Scheduled Pinned Locked Moved Unsolved Discuss
hstshttpserrorx509
3 Posts 3 Posters 518 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      L Offline
      LoudLemur
      wrote on last edited by LoudLemur
      #1

      After setting up a Cloudron site and installing an application on the bare domain, we tried to enable HSTS preloading. You can reach the site using an https:// address. The following error was returned when testing it here:
      https://hstspreload.org/

      Error: www subdomain does not support HTTPS
      Domain error: The www subdomain exists, but we couldn't connect to it using HTTPS ("tls: failed to verify certificate: x509: certificate is not valid for any names, but wanted to match www.haggis.top"). Since many people type this by habit, HSTS preloading would likely cause issues for your site.

      jdaviescoatesJ 1 Reply Last reply
      1
      • L LoudLemur marked this topic as a question on
      • L LoudLemur

        After setting up a Cloudron site and installing an application on the bare domain, we tried to enable HSTS preloading. You can reach the site using an https:// address. The following error was returned when testing it here:
        https://hstspreload.org/

        Error: www subdomain does not support HTTPS
        Domain error: The www subdomain exists, but we couldn't connect to it using HTTPS ("tls: failed to verify certificate: x509: certificate is not valid for any names, but wanted to match www.haggis.top"). Since many people type this by habit, HSTS preloading would likely cause issues for your site.

        jdaviescoatesJ Offline
        jdaviescoatesJ Offline
        jdaviescoates
        wrote on last edited by
        #2

        @LoudLemur I had no idea what HSTS Preloading is, but I just read https://www.howtogeek.com/devops/what-is-hsts-and-how-do-you-set-it-up/ and it sounds like it's best to proceed slowly with caution.

        In your case it sounds like you're missing a wildcard certificate that covers all subdomains including www.

        I use Cloudron with Gandi & Hetzner

        1 Reply Last reply
        1
        • girishG Offline
          girishG Offline
          girish
          Staff
          wrote on last edited by
          #3

          Have you seen https://docs.cloudron.io/apps/#hsts-preload ?

          1 Reply Last reply
          2
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • Bookmarks
            • Search