Hello! I set up Caddy last year and it’s been plugging along great since then but recently (a couple weeks ago?) the certificate for my root domain stopped working. When I visit that page I’m told the connection is insecure, and the certificate is expired. However, all of the subdomains still work properly. I am using Cloudflare for automatic certificates.
For what it’s worth the A record for my domain points to a Tailscale IP address so Cloudflare cannot ‘see’ the website though that hasn’t been a problem in the past. Any ideas as to what is going on? Does it have something to do with the www.queasy.cc > queasy.cc redirect?
2. Error messages and/or full log output:
Your connection is not private
net::ERR_CERT_DATE_INVALID
Per the previously reported experience, your resolver doesn’t like querying SOA records. Queries of A and AAAA records work fine, but are different. Try the workaround in the linked post and confirm it fixes your issue.
It seems like your domain is managed partially by Tailscale. The domain `_acme-challenge.queasy.cc` is CNAME-ed to Tailscle endpoint. This is likely wasn't there when you first set it up. I don't know much about the automatic-HTTPS of Tailscale, so you'll need to gather this information on your own or if another forum visitor or helper can pitch in.
Woah, good catch, thanks! I just checked the DNS settings for my domain over at Cloudflare and for some reason it had an entry of CNAME * [mytailnetdomain].ts.net. I sure don’t remember adding that but I guess I must have at some point? Either way when I deleted it everything started working again.