I was hitting it plaintext first, so a simple redirect to some subdomain instead of a bare redirect to https would probably work fine.
I was hitting it plaintext first, so a simple redirect to some subdomain instead of a bare redirect to https would probably work fine.
I don't trust letsencrypt and I don't want to give them or anyone else a list of which subdomains I use.
The certificate is only for "*.marginalia.nu", which simply doesn't cover "marginalia.nu". It should give the same error on any platform and browser, unless their SSL implementation is broken.
Some browsers try to be smart and insert www automatically though.
https://marginalia.nu = https://crt.sh/?id=6046506678 (includes wildcard but NOT apex)
https://search.marginalia.nu = https://crt.sh/?id=6125359537 (includes both wildcard and apex)
Don't really understand their motive either. Maybe they thought I was cloud hosted or used some expensive API to do searches and were attempting to rack up big bills or something.
I wish I had a good solution to this. Cloudflare to mitigate DDOS attacks has somewhat of a “baby with the bathwater” vibe (considering how much of a pain it is if you can't pass the CAPTCHA, or if you're on Tor), but I can't think of an alternative.
I've considered having a naked endpoint with a rate limiter that, when it hits some ceiling (dunno, sustained load of 2 RPS or so), offers the alternatives of going through an unlimited cloudflared domain, or waiting until the bots give up. But that might be annoying too.
Oof, I'm not sure if I would do that. Since "" stands for all sub domains.
When I visit https://search.marginalia.nu I'm served with this different cert, which does include both wildcard and apex: https://crt.sh/?id=6125359537