#7003 firewalld.org has broken HTTPS due to redirect
Closed: Fixed Opened by erig0.

I need someone to create an ALIAS record for firewalld.org to firewalld.github.io to fix SSL for https://firewalld.org. If ALIAS is not possible, then A records should be used (contents would be same as firewalld.github.io)

As per: https://help.github.com/articles/setting-up-an-apex-domain/#configuring-an-alias-or-aname-record-with-your-dns-provider

Below follows my original report via email.
--->8---

I'm the current project maintainer for firewalld and also maintain the content at firewalld.org.

At the moment https://firewalld.org results in a SSL error.

firewalld.org uses an invalid security certificate.
The certificate is only valid for the following names:
  *.redhat.com, redhat.com
  Error code: SSL_ERROR_BAD_CERT_DOMAIN

I think this came about because the website use to be hosted on
fedoraproject.org, but at some point was moved to github pages. When
that happened a redirect was setup. The current DNS record points to
redirect.redhat.com.

$ dig firewalld.org
firewalld.org.      82255   IN  A   209.132.183.105
$ dig -x 209.132.183.105
105.183.132.209.in-addr.arpa. 284 IN    PTR redirect.redhat.com.

This is all good for HTTP, but does not work for HTTPS as shown above.

Github suggests using an ALIAS or ANAME record for using github pages with custom domains [0]. This seems pretty straight forward and is just a matter of updating the DNS. This should alias firewalld.org to firewalld.github.io.

[0] https://help.github.com/articles/setting-up-an-apex-domain/#configuring-an-alias-or-aname-record-with-your-dns-provider

I hope that explains the issue well enough.


So, my email reply was:

 Unfortunately, ANAME/ALIAS records are not an actual official DNS record type.
They are basically "advertising" names for certain authorative DNS
server implementations that do CNAME flattening at the domain apex on
the DNS server side.
This is not something our setup supports unfortunately, since bind
does not have an implementation of this, and the fact that we actually
keep our DNSSEC keys offline.
So I'm afraid the best we could offer here is to manually do the CNAME
flattening now, and just have you ping us everytime GitHub Pages
decides to change their IP, but I'm not sure that that's something we
really want to (since during that time, it might be offline).

Unfortunately, I just checked, but it looks like Github pages is now fronted by fastly, which is a CDN, which often change actual IP addresses quite often.
So as said, while we could do manual flattening, this means a big risk that the domain apex will be unavailable for long periods if they changed the IPs.
That was the reason we often go for redirect.redhat.com: that IP address is static, and we'll be able to get a headsup way in advance if it ever changes.

@puiterwijk, I think if you use an A record requests will bypass the CDN and go to github directly [0]. While this is not ideal, it may be our best option.

[0] https://blog.github.com/2014-01-07-faster-more-awesome-github-pages/

DNS zonefie is updated: https://infrastructure.fedoraproject.org/cgit/dns.git/commit/?id=2de1a55.
It will take 15 minutes to synchronize out, and then 24 hours for local DNS caches to flush.

Metadata Update from @puiterwijk:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

Thanks @puiterwijk, I'll close this ticket once I can see the DNS changes on my end!

Metadata Update from @erig0:
- Issue status updated to: Open (was: Closed)

Metadata Update from @erig0:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

@erig0 sidenote: note that the certificate for https://www.firewalld.org/ has expired.

@puiterwijk, please check again. It has since been regenerated. It should all be good now. Looks fine on my end.

@erig0 unfortunately, I'm still being served the outdated certificate:
openssl s_client -showcerts -servername www.firewalld.org -connect www.firewalld.org:443
shows as cert:

-----BEGIN CERTIFICATE-----
MIIFBTCCA+2gAwIBAgISA1sHfQPBRl1QrrG0JMIWLK2CMA0GCSqGSIb3DQEBCwUA
MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0xODAyMjgxNzUwMjhaFw0x
ODA1MjkxNzUwMjhaMBwxGjAYBgNVBAMTEXd3dy5maXJld2FsbGQub3JnMIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA13xofFEfDCt/7rPq4JC8iVnWK2Qd
yOyIu0VJN0rCAFg7+qLjs/chgObvwRx3iAOkbva4ZRSAA/zdWmOYzQa0we5mEpJE
TCcZgOcjCzZSFvLw/A6GVukvGkJpQkJKAihUTVbtNjahSF8MdcY9zLansUfsAhAm
gLKZeX0Oo2EVtYufDIUVihvsDyWLd4XWF06BLE2t5WaN0762ep5I/NFL+DEwURrD
HOZX9WFOsDENSCGJrFZG2HGGTdDlvpKOGUsjvEgtGFiP95ONWFHCl1bZB/kUQNDV
tH02s2WkyZcjxusdJ3wuyTfLwRwFKcAFtdqCUYN0MV0WrJAObf5drKlb2QIDAQAB
o4ICETCCAg0wDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggr
BgEFBQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQI2tj5LPII3MVgf6Qn2AYn
PxW5jzAfBgNVHSMEGDAWgBSoSmpjBH3duubRObemRWXv86jsoTBvBggrBgEFBQcB
AQRjMGEwLgYIKwYBBQUHMAGGImh0dHA6Ly9vY3NwLmludC14My5sZXRzZW5jcnlw
dC5vcmcwLwYIKwYBBQUHMAKGI2h0dHA6Ly9jZXJ0LmludC14My5sZXRzZW5jcnlw
dC5vcmcvMBwGA1UdEQQVMBOCEXd3dy5maXJld2FsbGQub3JnMIH+BgNVHSAEgfYw
gfMwCAYGZ4EMAQIBMIHmBgsrBgEEAYLfEwEBATCB1jAmBggrBgEFBQcCARYaaHR0
cDovL2Nwcy5sZXRzZW5jcnlwdC5vcmcwgasGCCsGAQUFBwICMIGeDIGbVGhpcyBD
ZXJ0aWZpY2F0ZSBtYXkgb25seSBiZSByZWxpZWQgdXBvbiBieSBSZWx5aW5nIFBh
cnRpZXMgYW5kIG9ubHkgaW4gYWNjb3JkYW5jZSB3aXRoIHRoZSBDZXJ0aWZpY2F0
ZSBQb2xpY3kgZm91bmQgYXQgaHR0cHM6Ly9sZXRzZW5jcnlwdC5vcmcvcmVwb3Np
dG9yeS8wDQYJKoZIhvcNAQELBQADggEBADFyUEYX0NKSqK6+M3xV4VJmjS9UhIo2
uVrWBJSFHGhZfBZ3Tc5EWC+uByEkSoUzexXOSbsFy20Gi2kkd2cml2elCAa3CY9D
2ueTYxPXSKsRvf8jg7f77mOCeI2XK8KPd3Zo04e+ADg8lHTRiJoJ0tjQoRr1mdkc
TxwuTpKqWvrvivHM2S3yDMjmvM3ZY7YlL51eEKQVeETcx1/QiYUWqcAkY82ojgWQ
CzM6ZC+qnddNPtR0SpqyUVXrcQBfNAe3sXY+VfSohmnKYejr2DO+ZZqncw3J3bRP
Iq7aJX/Vn+E3QO+olk7Na8QV0whBBZRzcj/Jowgs5MFF1Tn1CvEw+lU=
-----END CERTIFICATE-----

x509 info:

        Validity
            Not Before: Feb 28 17:50:28 2018 GMT
            Not After : May 29 17:50:28 2018 GMT

Hrm..

https://firewalld.org works as expected
https://www.firewalld.org shows the expired cert

@puiterwijk, the current www CNAME points to firewalld.github.io. Should it point to firewalld.org instead?

;; ANSWER SECTION:
www.firewalld.org. 77305 IN CNAME firewalld.github.io.
firewalld.github.io. 3265 IN CNAME sni.github.map.fastly.net.
sni.github.map.fastly.net. 916 IN A 185.199.108.153
sni.github.map.fastly.net. 916 IN A 185.199.109.153
sni.github.map.fastly.net. 916 IN A 185.199.110.153
sni.github.map.fastly.net. 916 IN A 185.199.111.153

I filed a github ticket and their reply was essentially:

we only support certs on a single domain as specified by the repository settings.

As such, https://www.firewalld.org will not work and there is currently no way to fix it. We must use https://firewalld.org. All variants of the HTTP URLS will be upgraded to HTTPS - so http://www.firewalld.org does work.

Metadata