This server is currently running 443 but without TLS. I believe this is an error
What feature, service or problem is this related to?
I don’t know
What are the steps to reproduce the issue?
The server 172.67.70.114, which is one of the resolutions of the domain repo.protonvpn.com, appears to be running HTTP on port 80 and 443, but without running TLS on 443. This led to an error when trying to update packages for protonvpn.
Attempting connection to this node on 443 with TLS gives the error handshake error, or “SSL_ERROR_NO_CYPHER_OVERLAP”
I believe this is an error at some configuration level in CF.
I am on a network that appears to be filtering certain servers associated with VPNs, resetting peer connections on certain vpn sites, so it’s possible this is on my end, but this server issue appears to be an infrastructure issue.
Sorry, this is actually happening on multiple networks though.
Happening from US East, when connected on cable line networks like Cox, Comcast. It happened on another internet access node which isn’t doing the same connection reset blocking of VPN sites.
Are you able to check regionally if this is some multicast issue or something?
It happens on multiple devices from different egress networks (with different providers), all in US East region (now tested on 3). Tested on macOS, iOS and Ubuntu, same result.
It seems like it ends up serving a nonsecure plain HTTP instance on 443 as well as 80 for these.
Will be curious to see if you can find anything on CF end, and what is going on.