Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Let'sEncrypt wildcard cert not valid for base domain - self signed cloudron cert used instead

Let'sEncrypt wildcard cert not valid for base domain - self signed cloudron cert used instead

Scheduled Pinned Locked Moved Solved Support
letsencryptwildcardcertificatesubdomaindomain setup
4 Posts 3 Posters 1.6k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D Offline
    D Offline
    drbigman
    wrote on last edited by
    #1

    Greetings!

    I am pretty new to Cloudron - therefore first of all a very big thank you for the incredible valuable product, highly appreciated.

    If have just setup an instance of NextCloud at 'nxtcld.drbigman.org' - with domain 'drbigman.org' provided by porkbun. So far everything is working perfectly fine.

    However, when accessing base domain 'drbigman.org', a security warning is displayed and self-signed certificate (as provided for setup of my.drbigman.org from Cloudron) needs to be accepted.

    This issue is somewhat similar to the one described at https://forum.cloudron.io/topic/8270/lets-encrypt - however, in my case there is not even any web service configured for the base domain.

    As already mentioned: not a real problem at all. Besides showing a warning when accessing base domain, other effects include e.g. that SSL Server Test (https://www.ssllabs.com/ssltest/) will complain about a certificate mismatch when checking base domain (checking 'my.drbigman.org' returns perfect A+ for both IPv4/6).

    However, when I checked the Let'sEncrypt wildcard certificate as correctly used for 'nxtcld.drbigman.org', I noticed that it appears to only be issued for (wildcard) domains *.drbigman.org - but not in addition for 'drbigman.org', correct?

    IIRC, wildcard '.drbigman.org' does not include base domain 'drbigman.org' itself - but only subdomains. Therefore similar 'plain vanilla' certificates are frequently issued for '.drbigman.org, drbigman.org' - so that they also apply for the base domain.

    As recommended in ticket mentioned above, I have also renewed all certs thru dashboard - however, problem remains the same.

    Is there a certain reason, why LE cert is not issued for '*.drbigman.org, drbigman.org' - or may I have configured something incorrectly?

    Many thanks in advance for your support and advice.

    1 Reply Last reply
    0
    • nebulonN Away
      nebulonN Away
      nebulon
      Staff
      wrote on last edited by
      #2

      Seems like there is no app installed at http://drbigman.org/ ? For Cloudron the base domain/apex domain is just like any other subdomain, so by default nothing is served up there.

      1 Reply Last reply
      0
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #3

        In DNS, example.com is separate from app.example.com, app2.example.com and even www.example.com . One has to set up example.com manually to server something. The usual approach is that one has a website at www.example.com , then you can set up example.com to redirect to the other domain. See https://docs.cloudron.io/apps/#redirections

        This is how https://www.cloudron.io behaves. https://cloudron.io will redirect to the www subdomain.

        1 Reply Last reply
        0
        • girishG girish marked this topic as a question on
        • D Offline
          D Offline
          drbigman
          wrote on last edited by
          #4

          Hi @girish, hi @nebulon. Many thanks for perfect explanation, hope to have got that. Have now configured as explained above and apex domain does now also produces perfectly valid cert signed by LE. 👍🏼

          Many thanks also for impressingly quick response during weekend - appreciated. 😊

          1 Reply Last reply
          0
          • girishG girish has marked this topic as solved on

          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

          With your input, this post could be even better 💗

          Register Login
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • Bookmarks
          • Search