SSL errors since July 17

What is the name of the domain?

eforta.app

What is the error message?

SSL error: Hostname mismatch

What is the issue you’re encountering

Users accessing web and api via AMS datacenter are getting hostname mismatch ssl errors

What steps have you taken to resolve the issue?

Problem is on Cloudflare side.
For some reason, roughly 1/4 of all traffic to my application is going through AMS datacenter (rest via Prague, PRG). And that 1/4 stopped working since “AMS network issues” yesterday.

They are unable to connect via https, turnstile also won’t load etc.

It worked normally for months before yesterday

Also, I’m on Pro program, but can’t create a ticket as it still shows me as “Free” account. Can’t even load ticket dashboard, that’s why I’m writing it here.

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Full

Since “July 15”, of course. Sorry for that mistake

Web and api can theoretically be on two different hostnames.

What exact hostnames are causing issues?

What do you see under “Edge Certificates”?

https://dash.cloudflare.com/?to=/:account/:zone/ssl-tls/edge-certificates

Thank you for response!

Both web and api are on the same hostname.

In Edge certificates I see active universal certificate.

What is weird is, that for example I was unable to replicate the issue. Tried a few ISP (home, mobile, work), several browsers, my mobile app and none had this issue.

Users who reported this issue are mainly from Prague, which is weird, because I’m accesing the web via PRG datacenter.

Now I’ve tried VPN, jumped around Europe and was checking ../cdn-cgi/trace to see which Cloudflare location is used and everywhere it loaded just fine for me.

So either it was just fixed in the past hour or so, or it’s something related to their ISP/DNS setup (just my guess). I will try to get further feedback from them.

It sounds like an issue on Cloudflare’s AMS edge, especially since PRG works and the problem started after the AMS incident. A hostname mismatch at only one POP usually points to an edge certificate problem. I’d also have Cloudflare check why your Pro account is showing as Free so you can open a support ticket.

Before my previous post, I tried from the Netherlands, and saw no issues with any AMS pops that the sources of the traffic were able to hit.

  1. What ISP(s) / provider(s), preferably their AS number(s)?
    The AS number can be found here:
  • https://bgp.tools/
    → The AS number shown under “You are connecting from” like this: “Cloudflare, Inc. (AS13335)
  • https://bgp.he.net/
    → The AS number shown like this: “Your ISP is AS13335 (Cloudflare, Inc.)
  1. What country (and preferably state/region)?

  2. When exactly did this problem start?

Without more detailed information about source networks (AS numbers), … I would be suspecting that too.

Likely ISP/government based censorship, and if they’re overriding DNS responses to one of their own servers, which is very common, then their own server (and thus their “block page”) wouldn’t be able to serve a valid certificate for your domain name.

ISP/government censorship can result in many different (and strange) errors, and which exact one(s) you see, that depends on how exactly the censorship has been implemented.

OK, so this was a “false alarm”, sort of. It’s not cloudflare issue, but one of mobile ISP in Czech rep (O2) has their security tool, which uses some DB that marked our web as malicious. I’ve done several scans and it’s clean. I will request removal.
So, the only problem I have now is that Cloudflare considers my account as Free, even though I pay for Pro :slight_smile: . But that’s not something I can sort out here.
Thank you everyone who tried to help me.