Proxy and SSL for Web Builder product under Godaddy Websites + Marketing Basic

What is the name of the domain?

saulthousing com

What is the error number?

error 525

What is the error message?

SSL handshake failed

What is the issue you’re encountering

SSL handshake failed when using Cloudflare Proxy with SSL set to Full, Full (strict). Have not tested other methods.

What steps have you taken to resolve the issue?

Godaddy has an offering called Websites + Marketing Basic. It is not Wordpress. It does not have a cPanel that you can log into. It is a very basic drag and drop website builder that has zero configurable settings.
I moved DNS over to Cloudflare on Dec 12th and turned on Automatic Proxy and have had no issues until today.
I disabled the Cloudflare Proxy and after a few minutes the site was working again, but now with a freshly signed Godaddy cert Issued On Tuesday, January 14, 2025 at 9:26:43 AM Expires On Monday, April 14, 2025 at 10:26:43 AM

Coincidentally 9:26 AM is when I first visited the site after turning off the Cloudflare Proxy. So I assume that kicked off some automatic cert generation from Godaddy.

I turned the Cloudflare Proxy and set it to Full and after a few minutes traffic is now being proxied with my original cert from Dec 12th. Essentially I am back in business.

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Full

What are the steps to reproduce the issue?

I can only assume I have to wait until April 14, 2025 at 10:26:43 AM in order to reproduce this error as it is now working after Godaddy generated its own SSL and turning the Proxy back on.

Does anyone have any experience and recommendation on what mode I should set SSL in Cloudflare for this Godaddy Websites + Marketing Basic Web Builder product? Should I lower it even more to Flexible or Turn it off since Godaddy is generating an SSL?

Screenshot of the error

You need to change Cloudflare settings so that GoDaddy can still renew the certificate when the connection is proxied.

I believe you need to create a Configuration Rule that changes SSL mode to Off when URI Path begins with /.well-known/acme-challenge/

2 Likes

Great. I have applied the rule. Is there any way to test, or do I have to wait until April when the SSL expires again?

You probably need to wait. I can test if the rule works for me later.

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.