I use Cloudflare CDN to manage security on my domain. I've run into the same problem described in multiple threads where the LetsEncrypt certificate validation service fails due to cloudflare - the workaround is a cumbersome 'pause cloudflare on the domain every 3 months' and run AutoSSL. This becomes unmanageable as the number of accounts increases.
In an effort to find a solution, I disabled AutoSSL, removed the LetsEncrypt certificates and installed Cloudlare's Origin certificate instead.
This works perfectly for https but when I try to connect my mail client (Exim/Dovecot) they are presented with the root certificate for my domain, throwing a warning.
Understand that this has something to do with Domain TLS in cPanel, but have no idea where to look for a solution.
Any ideas please?
Webmail works, I get a 'B' on ssllabs.com (due to support of TLS 1.0 and 1.1)
Update: I have a theory that this is because Cloudflare's origin certificates are only valid to secure the connections between my server and cloudflare - I still need a certificate to secure the connection between clients and cloudflare CDN. Apologies for my limited knowledge in this area.
In an effort to find a solution, I disabled AutoSSL, removed the LetsEncrypt certificates and installed Cloudlare's Origin certificate instead.
This works perfectly for https but when I try to connect my mail client (Exim/Dovecot) they are presented with the root certificate for my domain, throwing a warning.
Understand that this has something to do with Domain TLS in cPanel, but have no idea where to look for a solution.
Any ideas please?
Webmail works, I get a 'B' on ssllabs.com (due to support of TLS 1.0 and 1.1)
Update: I have a theory that this is because Cloudflare's origin certificates are only valid to secure the connections between my server and cloudflare - I still need a certificate to secure the connection between clients and cloudflare CDN. Apologies for my limited knowledge in this area.
Last edited: