I don't trust letsencrypt and I don't want to give them or anyone else a list of which subdomains I use.
I don't trust letsencrypt and I don't want to give them or anyone else a list of which subdomains I use.
When I visit https://search.marginalia.nu I'm served with this different cert, which does include both wildcard and apex: https://crt.sh/?id=6125359537
Oof, I'm not sure if I would do that. Since "" stands for all sub domains.
The certificate is only for "*.marginalia.nu", which simply doesn't cover "marginalia.nu". It should give the same error on any platform and browser, unless their SSL implementation is broken.
Some browsers try to be smart and insert www automatically though.
https://marginalia.nu = https://crt.sh/?id=6046506678 (includes wildcard but NOT apex)
https://search.marginalia.nu = https://crt.sh/?id=6125359537 (includes both wildcard and apex)
Don't really understand their motive either. Maybe they thought I was cloud hosted or used some expensive API to do searches and were attempting to rack up big bills or something.
I wish I had a good solution to this. Cloudflare to mitigate DDOS attacks has somewhat of a “baby with the bathwater” vibe (considering how much of a pain it is if you can't pass the CAPTCHA, or if you're on Tor), but I can't think of an alternative.
I've considered having a naked endpoint with a rate limiter that, when it hits some ceiling (dunno, sustained load of 2 RPS or so), offers the alternatives of going through an unlimited cloudflared domain, or waiting until the bots give up. But that might be annoying too.