Page Rules SSL Error

Hi All, i am using page rule for one of my domain and i set SSL off to *.preview.reck.app but when i see the link http://1ebdc5-549dd.preview.reck.app i get SSL error, how to fix this once for preview sub domain? please advise.

The .app TLD has mandatory SSL:

I suggest you purchase Advanced Certificate Manager to generate a wildcard cert for the preview subdomains.

https://developers.cloudflare.com/ssl/edge-certificates/advanced-certificate-manager

3 Likes

Browsers enforce that, but other devices do not:

% curl  http://1ebdc5-549dd.preview.reck.app --dump-header - -o /dev/null --silent
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 03 Feb 2022 14:43:22 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Etag: "fffd24bdb71ba420b94a0448fbef9a28"
X-Butlerboost: HIT

Currently the hostname is :grey:, so the Page Rule does not apply anyway.

And the Page Rule as written would only apply to the root of the hostname, and not to any other URLs. Change the Page Rule to *.preview.reck.app/* to apply to everything under those hostnames.

The SSL: Off says that Cloudflare should talk to the Origin server over HTTP, and has no effect on the Client → Cloudflare connection.

4 Likes

@michael hi there, i changed the page rule to .preview.reck.app/ but still getting same error, also there is no record for .preview.reck.app in Cloudflare dns, do i need to add one?

As @sdayman said, you cannot use a browser to access ANY hostname on the .app domain over HTTP. (This is a decision made by the owner of the .app TLD, and is not something unique to Cloudflare). You need to talk to your hosting provider about getting a valid certificate on your server. If you want to make these hostnames :orange:, then you will need to subscribe to ACM as @sdayman said previously.

(I presume you actually said *.preview.reck.app.) You can either add a wildcard CNAME, but that can only ever be :grey: on any plans except Enterprise. Otherwise, create individual CNAME records rather than using the wildcard.

2 Likes

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.