Can you verify with wireshark that the traffic is only going through your lan? I’m not hip enough for nginx but I used to have to run apache under gdb all the time to trace random errors from the server. That would be next, if the traffic is really local.
Comment on Randomly getting ECH errors on self-hosted services.
Darkassassin07@lemmy.ca 1 month agoI do have external acces to Ombi via cloudflare; but the device I’m seeing this problem on is permanently connected to a VPN hosted from the same server machine as ombi/nginx with ‘block all connections without VPN’ enabled. And this testing has been done from within the same LAN.
It should never see/reach cloudflare for this service.
solrize@lemmy.world 1 month ago
Darkassassin07@lemmy.ca 1 month ago
I’ll look into that next if what I’ve done doesn’t work. (see other comments)
bobslaede@feddit.dk 1 month ago
Try with nslookup and see if you’re resolving the domain to both your local ipv4 address, and the Cloudflare ipv6 at the same time. I am using pihole for my local DNS, and it would give me both my local address, and also the Cloudflare ipv6 address.
Darkassassin07@lemmy.ca 1 month ago
Crap, looks like that’s exactly what it is.
Now how to fix that…
Darkassassin07@lemmy.ca 1 month ago
Added an AAAA record to pihole:
ombi.mydomain.example 0000:0000::0000:0000
Now nslookup returns the correct ipv4 address, and ‘::’ as the ipv6.
We’ll see if that works.
Darkassassin07@lemmy.ca 1 month ago
That unfortunately did not work. I am only getting the ipv4 address now, but I still get the same ECH error in chrome 1/5 tries.
Firefox now changed errors from ‘invalid certificate’ to ‘connection is insecure but this site has HSTS’. Still wont show the cert or provide any further info. (forgot to grab a screenshot before the below ‘solution’)
I’m really annoyed at this point and have just disabled cloudflare proxying for this service. That seems to have sorted it for all browsers. I may look further later, I may just say fuck it and leave it like this. Gotta walk away for a bit.
bobslaede@feddit.dk 1 month ago
You should change to use cname in pihole. I will write up on my computer later for you.