# Error 521 after latest update due to CloudFlare settings

**URL:** https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272
**Category:** Self-hosting
**Created:** [September 11, 2019, 1:56pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272 "2019-09-11T13:56:56Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Pravi](https://avatars.discourse-cdn.com/v4/letter/p/76d3ee/32.png) [@Pravi](https://meta.discourse.org/u/Pravi)
#### Post date: [September 11, 2019, 1:56pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/1 "2019-09-11T13:56:56Z")

</div>

Hello Guys!!

The whole site is down after update to the latest version. After the update, I rebooted the whole server. I am using Cloudflare. Don’t know what is the real issue. Need some serious help!!

> **[BG大游·(中国集团)官网](https://engineersasylum.com/)**
>
> 官方权威认可 ☀️可信指数高 ✅绿色安全标准

---

<div class="post-metadata">

### Author: ![christian\_01](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/christian_01/32/162392_2.png) [@christian\_01](https://meta.discourse.org/u/christian_01)
#### Post date: [September 11, 2019, 2:04pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/2 "2019-09-11T14:04:00Z")

</div>

I have the same issue!

[https://businesscomputingworld.co.uk](https://businesscomputingworld.co.uk/)

---

<div class="post-metadata">

### Author: ![Pravi](https://avatars.discourse-cdn.com/v4/letter/p/76d3ee/32.png) [@Pravi](https://meta.discourse.org/u/Pravi)
#### Post date: [September 11, 2019, 4:21pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/3 "2019-09-11T16:21:00Z")

</div>

Can you share a screenshot of your Cloudflare SSL settings?

 ![ssl](https://global.discourse-cdn.com/meta/original/3X/e/2/e2af749139b29c0f0516575ff0a5dca90ed239f0.png)

Have you tried this feature??

---

<div class="post-metadata">

### Author: ![Pravi](https://avatars.discourse-cdn.com/v4/letter/p/76d3ee/32.png) [@Pravi](https://meta.discourse.org/u/Pravi)
#### Post date: [September 11, 2019, 5:01pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/5 "2019-09-11T17:01:24Z")

</div>

I have removed my site from cloudflare and now my site is back online. Seems like cloudflare is the culprit.

---

<div class="post-metadata">

### Author: ![Zyniker](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/zyniker/32/120004_2.png) [@Zyniker](https://meta.discourse.org/u/Zyniker)
#### Post date: [September 11, 2019, 6:52pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/7 "2019-09-11T18:52:10Z")

</div>

I am(/was) having the [same issue](https://meta.discourse.org/t/discourse-fails-to-load-after-upgrade-to-2-4-0-beta4/128251) with [forum.confident.faith](https://forum.confident.faith). I can confirm that simply ‘pausing’ the site in the Cloudflare interface fixes the issue. This is particularly odd as I have several other sites with the same configuration _not_ experiencing this problem.

---

<div class="post-metadata">

### Author: ![christian\_01](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/christian_01/32/162392_2.png) [@christian\_01](https://meta.discourse.org/u/christian_01)
#### Post date: [September 11, 2019, 9:41pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/9 "2019-09-11T21:41:33Z")

</div>

How long did your site take to go back live once you re-pointed the DNS settings to Digital Ocean?

---

<div class="post-metadata">

### Author: ![Lagger\_Gandalf](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lagger_gandalf/32/128962_2.png) [@Lagger\_Gandalf](https://meta.discourse.org/u/Lagger_Gandalf)
#### Post date: [September 20, 2019, 8:47am UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/10 "2019-09-20T08:47:09Z")

</div>

Should be after 5 Seconds up to a minute, if your TTL is on Auto.

Depends on your TTL (Time to Life) Settings.

---

<div class="post-metadata">

### Author: ![thegurjyot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thegurjyot/32/120516_2.png) [@thegurjyot](https://meta.discourse.org/u/thegurjyot)
#### Post date: [September 20, 2019, 12:29pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/11 "2019-09-20T12:29:08Z")

</div>

My website is also not working after the update. I have updated TLS settings to 1.2 but still the website is not loading. Please tell what could be the issue and how to fix this?

---

<div class="post-metadata">

### Author: ![gerhard](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/gerhard/32/119479_2.png) [@gerhard](https://meta.discourse.org/u/gerhard)
#### Post date: [September 20, 2019, 12:39pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/12 "2019-09-20T12:39:20Z")

</div>

**Switching to TLS 1.2+ is definitely not the solution.**

Pleased compare your settings to the ones I posted in [After updating website wont come back online - #6 by gerhard](https://meta.discourse.org/t/after-updating-website-wont-come-back-online/128391/6). A rebuild of your Docker container, as mentioned in that post, might help too.

---

<div class="post-metadata">

### Author: ![thegurjyot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thegurjyot/32/120516_2.png) [@thegurjyot](https://meta.discourse.org/u/thegurjyot)
#### Post date: [September 20, 2019, 1:22pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/13 "2019-09-20T13:22:47Z")

</div>

I followed the instructions in that thread but my website is still not working. Can you please tell what could be the issue. I also replied in that thread with the error showing in my error logs.

---

<div class="post-metadata">

### Author: ![thegurjyot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thegurjyot/32/120516_2.png) [@thegurjyot](https://meta.discourse.org/u/thegurjyot)
#### Post date: [September 20, 2019, 8:37pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/14 "2019-09-20T20:37:12Z")

</div>

I tried to delete `./shared/standalone/ssl/website.com_ecc.cer` and `./shared/standalone/ssl/website.com_ecc.key` as stated by @gerhard in a private thread. And then I rebuild the app but the website is still not loading up. I unable to find the perfect solution for this. Please someone help me, as my website is down for more than 10 hours now.

Just check error logs and found this error there.

`nginx: [emerg] cannot load certificate "/shared/ssl/website.com_ecc.cer": PEM_read_bio_X509_AUX() failed (SSL: error:0909006C:PEM routines:get_name:no start line:Expecting: TRUSTED CERTIFICATE)`

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [September 20, 2019, 9:15pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/15 "2019-09-20T21:15:56Z")

</div>

I think that I had this problem on a site recently, but it had a couple of other issues so the details are fuzzy in my mind. You might try

```plaintext
rm -rf /var/discourse/shared/standalone/ssl
rm -rf /var/discourse/shared/standalone/letsencrypt

```

and then rebuild.

If you’re stuck and want to throw money at the problem, I’ll get you up and running for $300. I’m at my desk now. [Redirecting…](https://www.literatecomputing.com/product/rebuild-your-droplet/).

---

<div class="post-metadata">

### Author: ![thegurjyot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thegurjyot/32/120516_2.png) [@thegurjyot](https://meta.discourse.org/u/thegurjyot)
#### Post date: [September 20, 2019, 9:41pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/16 "2019-09-20T21:41:31Z")

</div>

I tried what you said and the website is still not loading. The logs still throwing the error

`nginx: [emerg] cannot load certificate "/shared/ssl/website.com.cer": PEM_read_bio_X509_AUX() failed (SSL: error:0909006C:PEM routines:get_name:no start line:Expecting: TRUSTED CERTIFICATE)`

I am really sorry but I am not in the condition of putting $300 out right now.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [September 20, 2019, 9:47pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/17 "2019-09-20T21:47:21Z")

</div>

$300 is a lot of money, but I’m pretty busy today (when I’m not waiting on the thing I’m testing to break). My last bit of free advice is to

```plaintext
cd /var/discourse/containers
grep DISCOURSE app.yml
mv app.yml app.broken
cd ..
./discourse-setup

```

This will generate a new app.yml. Perhaps you have something in it that’s causing the problem. The `grep` is so that you’ll have the information you need to answer the questions that `discourse-setup` requires.

---

<div class="post-metadata">

### Author: ![thegurjyot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thegurjyot/32/120516_2.png) [@thegurjyot](https://meta.discourse.org/u/thegurjyot)
#### Post date: [September 21, 2019, 6:13am UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/18 "2019-09-21T06:13:27Z")

</div>

I tried this but the setup didn’t start. Grep did work and I copied all data to a safe place so I can use it again. But now when I try to run the setup again it says

> This will show you what command is using port 80  
> COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME  
> docker-pr 27737 root 4u IPv6 47517368 0t0 TCP \*:http (LISTEN)
> 
> If you are trying to run Discourse simultaneously with another web  
> server like Apache or nginx, you will need to bind to a different port
> 
> See [Run other websites on the same machine as Discourse](https://meta.discourse.org/t/17247)
> 
> If you are reconfiguring an already-configured Discourse, use
> 
> ./launcher stop app
> 
> to stop Discourse before you reconfigure it and try again.

I think the situation is now just getting worse.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [September 21, 2019, 11:36am UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/19 "2019-09-21T11:36:00Z")

</div>

Sorry. You may have q more difficult problem than can be solved here

Given that your container file was banned app.yml, You need to first stop the old container with

```
docker stop app

```

Then discourse-setup can run.

I can’t imagine why the grep would not work.

---

<div class="post-metadata">

### Author: ![thegurjyot](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/thegurjyot/32/120516_2.png) [@thegurjyot](https://meta.discourse.org/u/thegurjyot)
#### Post date: [September 21, 2019, 12:06pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/20 "2019-09-21T12:06:26Z")

</div>

Hello @pfaffman, I am trying to fix this from hours and here is what I did. I was successful to remove the SSL and letsencrypt folder. Then I removed letsencrypt lines from app.yml and rebuild the app. Finally I removed https from cloudflare, after doing all of this the website is showing back again. But, now the website is not on https. I think I need to see what I should do from here.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [September 21, 2019, 2:04pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/21 "2019-09-21T14:04:02Z")

</div>

You need not to turn on the orange cloud from cloudflare. I hadn’t noticed that you were using cloudflare and if you had read the title of this topic you might have thought that it was the problem.

Just enable let’s encrypt in app.yml and it will work.

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [September 21, 2019, 2:27pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/22 "2019-09-21T14:27:42Z")

</div>

If you turn on the orange cloud then Let’s Encrypt cannot enrol or renew certificates.

---

<div class="post-metadata">

### Author: ![Ed\_Bobkov](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ed_bobkov/32/200014_2.png) [@Ed\_Bobkov](https://meta.discourse.org/u/Ed_Bobkov)
#### Post date: [May 19, 2020, 3:49pm UTC](https://meta.discourse.org/t/error-521-after-latest-update-due-to-cloudflare-settings/128272/23 "2020-05-19T15:49:28Z")

</div>

```
rm -rf /var/discourse/shared/standalone/ssl
rm -rf /var/discourse/shared/standalone/letsencrypt

```

thank you! that helped me!
