0

I have an HTTPS DNS record for fanaka.pro, pointing at readthedocs.io. My zone file:

fanaka.pro. 3600 IN HTTPS 0 readthedocs.io. fanaka.pro. 3600 IN NS ns1.desec.io. fanaka.pro. 3600 IN NS ns2.desec.org. fanaka.pro. 300 IN SOA get.desec.io. get.desec.io. 2025080201 86400 3600 2419200 3600 www.fanaka.pro. 3600 IN CNAME readthedocs.io. 

According to https://www.nslookup.io/domains/fanaka.pro/dns-records/https/:

QUESTION dig @ns2.desec.org. fanaka.pro. HTTPS ANSWER fanaka.pro. 3600 HTTPS 0 readthedocs.io. AUTHORITY ADDITIONAL . 0 OPT ; payload 1400, xrcode 0, version 0, flags 0 

Which looks correct. Running it locally I get a similar result (I had to install a newer version of dig, that supports HTTPS records):

fanaka.pro. 3600 IN HTTPS 0 readthedocs.io. 

What does that suggest and what should my next debugging step be?

6
  • https://fanaka.pro does not (my browser variously says it can't make a secure connection does it work without the HTTPS record? If so, the problem isn't the HTTPS DNS record. Commented Aug 4 at 22:07
  • 2
    The dig on your macOS is from long before rtype HTTPS was adopted (and long long past EOL) and according to this you need at least 9.17.18 with only 9.18 up supported upstream. I don't know why Apple is apparently giving you an old version and what you can do to get a newer one. What browser(s) are you using? Firefox may need help and I don't know about others. Commented Aug 5 at 3:45
  • @GregAskew Plain fanaka.pro doesn't work. Commented Aug 5 at 6:18
  • @dave_thompson_085 I tried with a newer version of dig and got the result I expected (question now updated). I have tried Safari, Chrome, Firefox. Commented Aug 5 at 6:21
  • 1
    Plain fanaka.pro doesn't work. The certificate needs the fanaka.pro name in the Subject Alternative Names. Commented Aug 5 at 8:27

0

You must log in to answer this question.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.