# 我的网站出现奇怪的SSL通知，无法访问

**URL:** https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246
**Category:** Self-hosting
**Created:** [2017年五月24日 00:14 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246 "2017-05-24T00:14:05Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![Yassine\_Yousfi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yassine_yousfi/32/195913_2.png) [@Yassine\_Yousfi](https://meta.discourse.org/u/Yassine_Yousfi)
#### Post date: [2017年五月24日 00:14 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/1 "2017-05-24T00:14:05Z")

</div>

My website has been running for a long time now, and suddenly today, after checking the traffic analytics noticed that it’s been down for the whole day. tried getting into the website and I get this error:

"Your connection is not private

Attackers might be trying to steal your information from [mydomain.com](http://mydomain.com) (for example, passwords, messages, or credit cards). NET::ERR\_CERT\_COMMON\_NAME\_INVALID"

 ![](https://global.discourse-cdn.com/meta/original/3X/e/a/ea75cf9541ac63862448eba170c783b29fe94abc.png)

I rebuilt the website, but nothing ☹ and checked CloudFlare it seems fine. Contacted Godaddy there was no issue from their side at all.

I’m confused now any ideas?

---

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [2017年五月24日 00:16 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/2 "2017-05-24T00:16:29Z")

</div>

Your site is presenting the wrong certificate, and has HSTS enabled. With the information available, there’s not a lot more detail we can give.

---

<div class="post-metadata">

### Author: ![Yassine\_Yousfi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yassine_yousfi/32/195913_2.png) [@Yassine\_Yousfi](https://meta.discourse.org/u/Yassine_Yousfi)
#### Post date: [2017年五月24日 00:21 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/3 "2017-05-24T00:21:42Z")

</div>

> [@mpalmer](#):
>
> HSTS

I didn’t enable it!

 ![](https://global.discourse-cdn.com/meta/original/3X/6/1/6181fc8443037bf18f23451625eeca8714c77c0f.png)

and more awkwardly, I didn’t touch any coding or server at all it just went down on its own!!! :o

---

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [2017年五月24日 00:26 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/4 "2017-05-24T00:26:45Z")

</div>

HSTS can be enabled by the origin server, it doesn’t have to be enabled by Cloudflare. If you ticked “force https” in your Discourse site’s settings, then that’ll do it.

If your site is being proxied by Cloudflare, then it’s a problem at their end, and not something wrong with Discourse. Otherwise, check the certificate you’ve configured Discourse to use, and ensure that it matches the name you’re using to access the site.

---

<div class="post-metadata">

### Author: ![Yassine\_Yousfi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yassine_yousfi/32/195913_2.png) [@Yassine\_Yousfi](https://meta.discourse.org/u/Yassine_Yousfi)
#### Post date: [2017年五月24日 00:41 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/5 "2017-05-24T00:41:17Z")

</div>

> [@mpalmer](#):
>
> If you ticked “force https” in your Discourse site’s settings

Yep, I’ve done that on discourse side loooong ago, and it’s been fine since then.

there is no way to contact cloudflare ☹ so is there a way I can “untick” the force https box from server side (as i can’t access my admin panel now). that way at least won’t be harmed that much 🙂

thanks

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [2017年五月24日 00:48 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/6 "2017-05-24T00:48:22Z")

</div>

Well, what you changed recently?

On Cloudflare DNS settings, is the cloud orange or gray? Try making it gray.

---

<div class="post-metadata">

### Author: ![Yassine\_Yousfi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yassine_yousfi/32/195913_2.png) [@Yassine\_Yousfi](https://meta.discourse.org/u/Yassine_Yousfi)
#### Post date: [2017年五月24日 01:07 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/7 "2017-05-24T01:07:03Z")

</div>

Changed absolutely nothing! 😳

the cloud is orange, just changed it but nothing changed :o

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [2017年五月24日 01:08 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/8 "2017-05-24T01:08:59Z")

</div>

When you change it from orange to gray, it changes the DNS entries, and it can take literally hours to propagate and update caches.

After you are sure the change is live, a rebuild should trigger a new cert (I’m assuming you are using our Let’s Encrypt setup).

---

<div class="post-metadata">

### Author: ![Yassine\_Yousfi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yassine_yousfi/32/195913_2.png) [@Yassine\_Yousfi](https://meta.discourse.org/u/Yassine_Yousfi)
#### Post date: [2017年五月24日 01:11 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/9 "2017-05-24T01:11:17Z")

</div>

I followed these instructions from sam.

> [@Allow SSL / HTTPS for your Discourse Docker setup](https://meta.discourse.org/t/allowing-ssl-https-for-your-discourse-docker-setup/13847):
>
> This guide is likely out of date as there are now very few reasons not to use the built-in Let’s Encrypt certificate that Just Works. See also: 2023-04-10 @pfaffman says: This is left here mostly for historical purposes. So you’d like to enable SSL for your Docker-based Discourse setup? Let’s do it! This guide assumes you used all the [standard install](https://meta.discourse.org/t/142537?silent=true) defaults – a container configuration file at/var/discourse/containers/app.yml and Discourse docker is installed at: /var/discourse Buy a SS…

Yep, will be waiting.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [2017年五月24日 01:13 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/10 "2017-05-24T01:13:27Z")

</div>

So you bought a certificate? Maybe it expired? Did you check that?

---

<div class="post-metadata">

### Author: ![Yassine\_Yousfi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yassine_yousfi/32/195913_2.png) [@Yassine\_Yousfi](https://meta.discourse.org/u/Yassine_Yousfi)
#### Post date: [2017年五月24日 01:16 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/11 "2017-05-24T01:16:09Z")

</div>

Nop, I used free shared one 🙂 I don’t buy certificates 🕶

---

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [2017年五月24日 01:27 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/12 "2017-05-24T01:27:52Z")

</div>

> [@Yassine\_Yousfi](#):
>
> is there a way I can “untick” the force https box from server side

Yes, but it won’t do any good, as any previous visitor to the site will have remembered that HTTPS is supposed to be enabled, and will fail to connect (as shown in the error you originally pasted).

> [@Yassine\_Yousfi](#):
>
> I used free shared one

Define “shared one”.

You’re really not helping us help you here. Please describe your exact setup, including the actual domain name at issue, where you got the certificate from and when, all the servers and proxies in your chain, and so on. Then we might have a hope of spotting what’s gone wrong. At the moment, it’s an endless game of psychic debugging, which is clearly not working.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [2017年五月24日 01:29 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/13 "2017-05-24T01:29:10Z")

</div>

If you shared your site name then people could look at your certificate and have more information to help you like whether DNS changes have propagated.

My best guess is that whatever certificate you got is expired. Can you say how or where you got it? The instructions you linked to don’t describe how to get a certificate.

The simplest solution would be to turn off cloudflare and rebuild your site with Let’s Encrypt.

You can turn off force\_https like this:

```bash
cd /var/discourse
./launcher enter app
rails c
SiteSetting.force_https=false
exit
exit

```

But most browsers (like yours) will remember that the site is supposed to be https and will try very hard not to connect. Or, more elegantly:

> [@mpalmer](#):
>
> but it won’t do any good, as any previous visitor to the site will have remembered that HTTPS is supposed to be enabled, and will fail to connect (as shown in the error you originally pasted).

---

<div class="post-metadata">

### Author: ![Yassine\_Yousfi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yassine_yousfi/32/195913_2.png) [@Yassine\_Yousfi](https://meta.discourse.org/u/Yassine_Yousfi)
#### Post date: [2017年五月24日 01:33 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/14 "2017-05-24T01:33:09Z")

</div>

My domain name is: [stopbyte.com](http://stopbyte.com)

I’ve tried this: [SSL Server Test: stopbyte.com (Powered by Qualys SSL Labs)](https://www.ssllabs.com/ssltest/analyze.html?d=stopbyte.com#whyNotTrusted)

any help now?  
thanks

---

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [2017年五月24日 01:39 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/15 "2017-05-24T01:39:42Z")

</div>

> [@pfaffman](#):
>
> My best guess is that whatever certificate you got is expired.

That’s a separate error message to “common name invalid”.

Even better, `stopbyte.com` isn’t emitting that error any more, it’s not saying the cert isn’t trusted, because it’s now presenting the Cloudflare special “Origin Certificate”, which is only trusted by Cloudflare. Put back the certificate you had before, and see what happens.

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [2017年五月24日 02:22 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/16 "2017-05-24T02:22:12Z")

</div>

> [@Falco](#):
>
> it can take literally hours to propagate and update caches.

The TTL used by CloudFlare is only 300 seconds.

HSTS specifically takes longer because the browser has retained the instruction. For example on Chrome you can visit chrome://net-internals/#hsts and remove a domain, which will immediately bypass the old HSTS instruction.

> [@Yassine\_Yousfi](#):
>
> My domain name is: [stopbyte.com](http://stopbyte.com)

Are you referring to the default shared SSL that CloudFlare implements? If not what’s the source?

In your app.yml did you enable support for Let’s Encrypt by uncommenting the entries for web.template.ssl and web.letsencrypt.ssl.template? They’re all you need for HTTPS at the server end. Once they’re working you can safely enable strict HTTPS at CloudFlare.

---

<div class="post-metadata">

### Author: ![Yassine\_Yousfi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yassine_yousfi/32/195913_2.png) [@Yassine\_Yousfi](https://meta.discourse.org/u/Yassine_Yousfi)
#### Post date: [2017年五月24日 02:42 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/17 "2017-05-24T02:42:40Z")

</div>

Phew Thanks a lot, this was really a terribly long day 😩

That solved my problem, I think the issue been that there were tons of tutorials on this website on setting the SSL correctly and I guess I mixed them up.

It will be helpful having one unique simple tutorial (as you put it on your post) on doing this. and taking down the others.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [2017年五月24日 03:37 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/18 "2017-05-24T03:37:34Z")

</div>

Glad you got it fixed!

> [@Yassine\_Yousfi](#):
>
> That solved my problem, I think the issue been that there were tons of tutorials on this website on setting the SSL correctly and I guess I mixed them up.

You still haven’t described what was wrong or how you fixed it, so it’s difficult to know which tutorial you found useful.

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [2024年六月8日 12:44 UTC](https://meta.discourse.org/t/my-site-is-down-with-a-weird-ssl-notification/63246/19 "2024-06-08T12:44:39Z")

</div>

该主题在 2572 天后自动关闭。不再允许回复。
