<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=5449&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / [SOLVED] SSL Report - What to Fix & Ignore]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=5449</link>
		<description><![CDATA[The most recent posts in [SOLVED] SSL Report - What to Fix & Ignore.]]></description>
		<lastBuildDate>Thu, 05 Jan 2023 14:36:13 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: [SOLVED] SSL Report - What to Fix & Ignore]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=40006#p40006</link>
			<description><![CDATA[<div class="quotebox"><cite>dcolburn wrote:</cite><blockquote><div><p>I&#039;m guessing I need to figure out why DNS CAA isn&#039;t being reported ... <strong>DNS CAA&#160; &#160; &#160;No (more info)</strong></p></div></blockquote></div><p>This is set by your domain registrar.&#160; Log into the site that you registered the domain name, and add a CAA record using the issuer of your certificate.&#160; <a href="https://letsencrypt.org/docs/caa/" rel="nofollow">https://letsencrypt.org/docs/caa/</a> may have more information.&#160; One of my CAA records looks like this:<br />example.com 1799 IN CAA 0 issue &quot;letsencrypt.org&quot;</p><p>Unfortunately, I don&#039;t know what to make of those handshake failures.&#160; That seems unrelated to caa.</p>]]></description>
			<author><![CDATA[dummy@example.com (rbit)]]></author>
			<pubDate>Thu, 05 Jan 2023 14:36:13 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=40006#p40006</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] SSL Report - What to Fix & Ignore]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=40005#p40005</link>
			<description><![CDATA[<p>Shutting down for the night but will try this tomorrow ... unless directed elsewhere ...</p><p><span class="bbc">https://www.linuxbabe.com/ubuntu/dns-over-tls-resolver-nginx</span> </p><p><strong>Step 3: Create DNS over TLS Proxy in Nginx</strong></p>]]></description>
			<author><![CDATA[dummy@example.com (dcolburn)]]></author>
			<pubDate>Thu, 05 Jan 2023 03:57:35 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=40005#p40005</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] SSL Report - What to Fix & Ignore]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=40004#p40004</link>
			<description><![CDATA[<p>These are the last few lines of output from <span class="bbc">https://unboundtest.com</span> for CAA.</p><div class="codebox"><pre><code>Jan 05 03:47:24 unbound[729481:0] info: reply from &lt;com.&gt; 192.41.162.30#53
Jan 05 03:47:24 unbound[729481:0] info: query response was ANSWER
Jan 05 03:47:24 unbound[729481:0] info: validated DNSKEY com. DNSKEY IN
Jan 05 03:47:24 unbound[729481:0] info: resolving realupnow.com. DS IN
Jan 05 03:47:24 unbound[729481:0] info: response for realupnow.com. DS IN
Jan 05 03:47:24 unbound[729481:0] info: reply from &lt;com.&gt; 2001:503:d2d::30#53
Jan 05 03:47:24 unbound[729481:0] info: query response was nodata ANSWER
Jan 05 03:47:24 unbound[729481:0] info: NSEC3s for the referral proved no DS.
Jan 05 03:47:24 unbound[729481:0] info: Verified that unsigned response is INSECURE
Jan 05 03:47:24 unbound[729481:0] info: 127.0.0.1 realupnow.com. CAA IN NOERROR 1.528696 0 101</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (dcolburn)]]></author>
			<pubDate>Thu, 05 Jan 2023 03:50:20 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=40004#p40004</guid>
		</item>
		<item>
			<title><![CDATA[[SOLVED] SSL Report - What to Fix & Ignore]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=40003#p40003</link>
			<description><![CDATA[<p>Suggestions as to what I should address vs ignore?</p><p>I just ran this free analysis ... <span class="bbc">https://www.ssllabs.com/ssltest/analyze.html</span></p><p>I&#039;m guessing I need to figure out why DNS CAA isn&#039;t being reported ... <strong>DNS CAA&#160; &#160; &#160;No (more info)</strong></p><p>Should I just ignore the rest of this?</p><div class="codebox"><pre><code>IE 11 / Win Phone 8.1  R		Server sent fatal alert: handshake_failure
Safari 6 / iOS 6.0.1 	Server sent fatal alert: handshake_failure
Safari 7 / iOS 7.1  R		Server sent fatal alert: handshake_failure
Safari 7 / OS X 10.9  R		Server sent fatal alert: handshake_failure
Safari 8 / iOS 8.4  R		Server sent fatal alert: handshake_failure
Safari 8 / OS X 10.10  R		Server sent fatal alert: handshake_failure</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (dcolburn)]]></author>
			<pubDate>Thu, 05 Jan 2023 02:42:38 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=40003#p40003</guid>
		</item>
	</channel>
</rss>
