This hostname is not covered by a certificate unable to remove site from Cloudflare

What is the name of the domain?

ghw.photography and ghwphotography.com

What is the error message?

This hostname is not covered by a certificate.

What is the issue you’re encountering

Receiving the error message “This hostname is not covered by a certificate.” on the A records pointed to DreamHost. Cloudflare is the registrar for both of these sites. I have other sites that are registered through Cloudflare and hosted on Dreamhost that do not have this issue.

What steps have you taken to resolve the issue?

Tried removing the site from Cloudflare temporarily to re-add it and hopefully reset it to fix this certificate error.

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Full (strict)

What are the steps to reproduce the issue?

This issue originally happened on ghw.photography while ghwphotography.com was being redirected through a page rule to the ghw.photography URL. I hoped that in the meantime I could use ghwphotography.com so I removed the redirect page rule, but the same error is happening.

Screenshot of the error

Make sure the domain is active on Cloudflare, you should see this at the top of the page in your dashboard…

It seems the domain is active on Cloudflare but there’s no edge certificate…
https://cf.sjr.dev/tools/check?c35b3c7a18274e26982bcd70f6a5a0fe#connection-server-https

If it is, check Universal SSL is enabled at the bottom of this page…
https://dash.cloudflare.com/?to=/:account/:zone/ssl-tls/edge-certificates

If it is enabled, disable it, wait a few minutes, then enable it again to see if that fixes it. Only do that once so rate limits don’t stop the certificate being issued.

Thanks for the suggestion but they were both already active.

Then do this :point_down:

Oop, didn’t see the bottom half of that message. I disabled the Universal SSL and waiting a couple minutes to re-enable it. Thanks; I’ll update if that fixed the issue

Note also that ssh and ftp need to be set to “DNS only” and not “Proxied” if you use those services. You can also delete the NS records for the apex domain as they don’t do anything.

1 Like

Thanks for the tip. I’ll fix the ssh and ftp A records to be DNS only. Not sure where the NS record for the apex domain is, I only have the three nameservers that DreamHost says to use.

Re-enabling the Universal SSL didn’t seem to fix the issue. When it was off, it looked like the error was gone, but when I turned it back on, that same error message returned.

I was able to at least restore service to all the effected sites by disabling Cloudflare. Would still love to know of a solution so I can use their CDN and proxy services.