Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. AdGuard Home
  3. AdGuard Home Wildcard aliases

AdGuard Home Wildcard aliases

Scheduled Pinned Locked Moved Solved AdGuard Home
porkbunwildcard
56 Posts 6 Posters 9.5k Views 6 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • girishG girish

    @lukas Yeah, so they never got back 😕 I even sent them a reminder. Please point them to this thread (if you are a customer). I sent mails from girish@cloudron.io

    Unfortunately, one cannot create a wildcard certificate from the Wildcard Domain. This is because Let's Encrypt requires you to set values in the DNS to get a wildcard cert. With a wildcard provider, Cloudron has no way to program the DNS. Only fix right now is to switch to some other programmable DNS provider. Sorry...

    L Offline
    L Offline
    lukas
    wrote on last edited by lukas
    #30

    @girish is there any other way to do this? I switched my Nameservers to Bunny.net from this domain, so I wait to next cloudron release 🙂

    girishG 1 Reply Last reply
    0
    • L lukas

      @girish is there any other way to do this? I switched my Nameservers to Bunny.net from this domain, so I wait to next cloudron release 🙂

      girishG Offline
      girishG Offline
      girish
      Staff
      wrote on last edited by
      #31

      @lukas Yup, so in next release, it should work 🤞 You have to switch to some other provider for something immediate (like today).

      L 1 Reply Last reply
      1
      • girishG girish

        @lukas Yup, so in next release, it should work 🤞 You have to switch to some other provider for something immediate (like today).

        L Offline
        L Offline
        lukas
        wrote on last edited by
        #32

        @girish ok, then I will wait for next release. Will it come today? 🙂

        1 Reply Last reply
        0
        • girishG girish

          @lukas Yeah, so they never got back 😕 I even sent them a reminder. Please point them to this thread (if you are a customer). I sent mails from girish@cloudron.io

          Unfortunately, one cannot create a wildcard certificate from the Wildcard Domain. This is because Let's Encrypt requires you to set values in the DNS to get a wildcard cert. With a wildcard provider, Cloudron has no way to program the DNS. Only fix right now is to switch to some other programmable DNS provider. Sorry...

          L Offline
          L Offline
          lukas
          wrote on last edited by
          #33

          @girish said in AdGuard Home Wildcard aliases:

          Yeah, so they never got back I even sent them a reminder. Please point them to this thread (if you are a customer). I sent mails from girish@cloudron.io

          you got maybe any ticket number? I will contact them now

          girishG 1 Reply Last reply
          0
          • L lukas

            @girish said in AdGuard Home Wildcard aliases:

            Yeah, so they never got back I even sent them a reminder. Please point them to this thread (if you are a customer). I sent mails from girish@cloudron.io

            you got maybe any ticket number? I will contact them now

            girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by
            #34

            @lukas they didn't give me one.

            L 1 Reply Last reply
            1
            • girishG girish

              @lukas they didn't give me one.

              L Offline
              L Offline
              lukas
              wrote on last edited by
              #35

              @girish update to latest Cloudron Version, bunny.net integration is working fine (thanks for this), but DoT on my Android Phone is still not working, in AdGuard Home Log I see:

              May 02 10:35:57 2023/05/02 08:35:57.599729 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
              May 02 10:35:57 2023/05/02 08:35:57.907614 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
              May 02 10:35:57 2023/05/02 08:35:57.914408 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
              

              What is wrong? I use <clientname>.adguard.mydomain.TLD and I added an Alias (*.adgaurd) to AdGuard Home.

              What is wrong?

              Thank you and Regards,
              Lukas

              girishG 1 Reply Last reply
              0
              • L lukas

                @girish update to latest Cloudron Version, bunny.net integration is working fine (thanks for this), but DoT on my Android Phone is still not working, in AdGuard Home Log I see:

                May 02 10:35:57 2023/05/02 08:35:57.599729 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
                May 02 10:35:57 2023/05/02 08:35:57.907614 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
                May 02 10:35:57 2023/05/02 08:35:57.914408 [error] handling tcp: reading msg: reading len: remote error: tls: bad certificate
                

                What is wrong? I use <clientname>.adguard.mydomain.TLD and I added an Alias (*.adgaurd) to AdGuard Home.

                What is wrong?

                Thank you and Regards,
                Lukas

                girishG Offline
                girishG Offline
                girish
                Staff
                wrote on last edited by
                #36

                @lukas If you go to Location view and click Save (without making any changes), does that help the situation ? That should maybe (re)trigger getting the cert.

                L 1 Reply Last reply
                0
                • girishG girish

                  @lukas If you go to Location view and click Save (without making any changes), does that help the situation ? That should maybe (re)trigger getting the cert.

                  L Offline
                  L Offline
                  lukas
                  wrote on last edited by
                  #37

                  @girish did not help. This looks also not fine:

                  bdca3c66-576e-4891-b1b3-9026d9d2be43-image.png

                  Certificate chain is invalid

                  girishG 1 Reply Last reply
                  0
                  • L lukas

                    @girish did not help. This looks also not fine:

                    bdca3c66-576e-4891-b1b3-9026d9d2be43-image.png

                    Certificate chain is invalid

                    girishG Offline
                    girishG Offline
                    girish
                    Staff
                    wrote on last edited by
                    #38

                    @lukas can you check the output of openssl x509 -text -in /etc/certs/_.adguard.domain.cert in the web terminal of adguard ? Does it seem like a valid Let's Encrypt certificate?

                    L 1 Reply Last reply
                    0
                    • girishG girish

                      @lukas can you check the output of openssl x509 -text -in /etc/certs/_.adguard.domain.cert in the web terminal of adguard ? Does it seem like a valid Let's Encrypt certificate?

                      L Offline
                      L Offline
                      lukas
                      wrote on last edited by
                      #39

                      @girish I see an output. Which part do you need from this ouput?

                      girishG 1 Reply Last reply
                      0
                      • L lukas

                        @girish I see an output. Which part do you need from this ouput?

                        girishG Offline
                        girishG Offline
                        girish
                        Staff
                        wrote on last edited by
                        #40

                        @lukas The first few lines should give us the issuer and expiry like this:

                        Certificate:
                            Data:
                                Version: 3 (0x2)
                                Serial Number:
                                    04:1d:71:e7:48:c7:d3:80:02:ac:c1:ac:5b:79:e5:3f:3e:4e
                                Signature Algorithm: sha256WithRSAEncryption
                                Issuer: C = US, O = Let's Encrypt, CN = R3
                                Validity
                                    Not Before: Apr 15 02:11:00 2023 GMT
                                    Not After : Jul 14 02:10:59 2023 GMT
                        

                        Then later down, you should also see the SAN section:

                                    X509v3 Subject Alternative Name: 
                                        DNS:*.girish.in
                        

                        Ideally, there should the wildcard and non-wildcard DNS listed above in your case.

                        L 1 Reply Last reply
                        0
                        • girishG girish

                          @lukas The first few lines should give us the issuer and expiry like this:

                          Certificate:
                              Data:
                                  Version: 3 (0x2)
                                  Serial Number:
                                      04:1d:71:e7:48:c7:d3:80:02:ac:c1:ac:5b:79:e5:3f:3e:4e
                                  Signature Algorithm: sha256WithRSAEncryption
                                  Issuer: C = US, O = Let's Encrypt, CN = R3
                                  Validity
                                      Not Before: Apr 15 02:11:00 2023 GMT
                                      Not After : Jul 14 02:10:59 2023 GMT
                          

                          Then later down, you should also see the SAN section:

                                      X509v3 Subject Alternative Name: 
                                          DNS:*.girish.in
                          

                          Ideally, there should the wildcard and non-wildcard DNS listed above in your case.

                          L Offline
                          L Offline
                          lukas
                          wrote on last edited by lukas
                          #41

                          @girish

                          Certificate:
                              Data:
                                  Version: 3 (0x2)
                                  Serial Number:
                                      36:5d:97:51:3d:9f:45:89:58:45:67:c2:82:a6:83:3f:6d:50:69:0b
                                  Signature Algorithm: sha256WithRSAEncryption
                                  Issuer: CN = *.mydomain.cloud
                                  Validity
                                      Not Before: Apr  2 14:06:15 2023 GMT
                                      Not After : Jun 10 14:06:15 2025 GMT
                          

                          and

                          			        X509v3 extensions:
                                      X509v3 Subject Alternative Name: 
                                          DNS:mydomain.cloud, DNS:*.mydomain.cloud
                          
                          girishG 1 Reply Last reply
                          0
                          • L lukas

                            @girish

                            Certificate:
                                Data:
                                    Version: 3 (0x2)
                                    Serial Number:
                                        36:5d:97:51:3d:9f:45:89:58:45:67:c2:82:a6:83:3f:6d:50:69:0b
                                    Signature Algorithm: sha256WithRSAEncryption
                                    Issuer: CN = *.mydomain.cloud
                                    Validity
                                        Not Before: Apr  2 14:06:15 2023 GMT
                                        Not After : Jun 10 14:06:15 2025 GMT
                            

                            and

                            			        X509v3 extensions:
                                        X509v3 Subject Alternative Name: 
                                            DNS:mydomain.cloud, DNS:*.mydomain.cloud
                            
                            girishG Offline
                            girishG Offline
                            girish
                            Staff
                            wrote on last edited by
                            #42

                            @lukas It's not getting the new certs for some reason - it's using the self-signed cert. If you go to Domains -> Renew all certs. Can you check the logs when it's renewing? Do you see any errors?

                            L 1 Reply Last reply
                            0
                            • girishG girish

                              @lukas It's not getting the new certs for some reason - it's using the self-signed cert. If you go to Domains -> Renew all certs. Can you check the logs when it's renewing? Do you see any errors?

                              L Offline
                              L Offline
                              lukas
                              wrote on last edited by
                              #43

                              @girish I sent you the log-file via E-Mail

                              girishG 1 Reply Last reply
                              0
                              • L lukas

                                @girish I sent you the log-file via E-Mail

                                girishG Offline
                                girishG Offline
                                girish
                                Staff
                                wrote on last edited by
                                #44

                                @lukas From the logs, it seems the domain is not using Wildcard certs at all. If you go to Domains -> Edit -> Advanced. What is the certificate provider ? I suspect it's not wildcard . Can you change it and try to renew certs again?

                                I guess the reason is because you went from maybe Wildcard DNS to Programmatic DNS. In wildcard DNS, wildcard cert is not possible. But this is indeed a workflow/ui thing, that we have to consider in the future.

                                girishG 1 Reply Last reply
                                0
                                • girishG girish

                                  @lukas From the logs, it seems the domain is not using Wildcard certs at all. If you go to Domains -> Edit -> Advanced. What is the certificate provider ? I suspect it's not wildcard . Can you change it and try to renew certs again?

                                  I guess the reason is because you went from maybe Wildcard DNS to Programmatic DNS. In wildcard DNS, wildcard cert is not possible. But this is indeed a workflow/ui thing, that we have to consider in the future.

                                  girishG Offline
                                  girishG Offline
                                  girish
                                  Staff
                                  wrote on last edited by
                                  #45

                                  The certificate provider should be Let's Encrypt Prod - Wildcard

                                  L 2 Replies Last reply
                                  0
                                  • girishG girish

                                    The certificate provider should be Let's Encrypt Prod - Wildcard

                                    L Offline
                                    L Offline
                                    lukas
                                    wrote on last edited by
                                    #46

                                    @girish this is set and I haven't change it. Just today changed the DNS Provider from Wildcard to Bunny

                                    57f1d68f-ae04-4dab-9c26-02744c411ad3-image.png

                                    1 Reply Last reply
                                    0
                                    • girishG girish

                                      The certificate provider should be Let's Encrypt Prod - Wildcard

                                      L Offline
                                      L Offline
                                      lukas
                                      wrote on last edited by
                                      #47

                                      @girish so which steps do I need to go, to get this resolved?

                                      Btw. I see there some "non-used" SSL certificates, is there any kind of "housekeeping" ?

                                      girishG 1 Reply Last reply
                                      0
                                      • L lukas

                                        @girish so which steps do I need to go, to get this resolved?

                                        Btw. I see there some "non-used" SSL certificates, is there any kind of "housekeeping" ?

                                        girishG Offline
                                        girishG Offline
                                        girish
                                        Staff
                                        wrote on last edited by
                                        #48

                                        @lukas I am a bit lost at this point. Are you able contact me at support@cloudron.io , so I can debug your instance?

                                        L 1 Reply Last reply
                                        0
                                        • girishG girish

                                          @lukas I am a bit lost at this point. Are you able contact me at support@cloudron.io , so I can debug your instance?

                                          L Offline
                                          L Offline
                                          lukas
                                          wrote on last edited by
                                          #49

                                          @girish sure, I give you access. I open a Ticket via Cloudron

                                          girishG 1 Reply Last reply
                                          1
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Bookmarks
                                          • Search