Darkassassin07

joined 1 year ago
[–] Darkassassin07@lemmy.ca 1 points 1 hour ago

I think I've found the problem:

It seems my issue is pihole being unable to block/modify dns requests for HTTPS records, which don't match the LAN IPs pihole handed out in A/AAAA records.

I've disabled cloudflare proxying so they don't have HTTPS records to serve, but I'll have to replace pihole with a better lan DNS solution if I want to turn that back on.

[–] Darkassassin07@lemmy.ca 1 points 1 hour ago* (last edited 1 hour ago)

Thanks. That seems to be a similar, but slightly different error. I think the below may apply though.

I believe I've tracked down more of my issue, but fixing it is going to be a hassle:

When cloudflare proxying is enabled, there are 3 DNS records involved; A record with cloudflares ipv4, AAAA record with cloudflares IPV6, and the key to this puzzle: an HTTPS record with cloudflares ech/https config.

With pihole I can set DNS records for A/AAAA, but I have no way of blocking/setting the HTTPS record so it gets through from cloudflare.

The LAN A/AAAA records don't match the HTTPS record from cloudflare, so browsers freak out.

Once I disabled cloudflares proxying, I no longer get HTTPS records returned and all works as intended.

I'll either have to keep cloudflare proxying disabled, or switch pihole out for a more comprehensive DNS solution so I can set/block HTTPS records :(

Thank you @bobslaede@feddit.dk for pointing me in the right direction.

[–] Darkassassin07@lemmy.ca 1 points 1 hour ago* (last edited 1 hour ago)

That unfortunately did not work. I am only getting the ipv4 address now, but I still get the same ECH error in chrome 1/5 tries.

Firefox now changed errors from 'invalid certificate' to 'connection is insecure but this site has HSTS' (true). Still wont show the cert or provide any further info. (forgot to grab a screenshot before the below 'solution')

I'm really annoyed at this point and have just disabled cloudflare proxying for this service. That seems to have sorted it for all browsers. I may look further later, I may just say fuck it and leave it like this. Gotta walk away for a bit.

[–] Darkassassin07@lemmy.ca 1 points 2 hours ago

I'll look into that next if what I've done doesn't work. (see other comments)

[–] Darkassassin07@lemmy.ca 1 points 2 hours ago (1 children)

Added an AAAA record to pihole:

ombi.mydomain.example 0000:0000::0000:0000

Now nslookup returns the correct ipv4 address, and '::' as the ipv6.

We'll see if that works.

[–] Darkassassin07@lemmy.ca 2 points 2 hours ago

Crap, looks like that's exactly what it is.

Now how to fix that...

[–] Darkassassin07@lemmy.ca 1 points 2 hours ago* (last edited 2 hours ago) (6 children)

I do have external acces to Ombi via cloudflare; but the device I'm seeing this problem on is permanently connected to a VPN hosted from the same server machine as ombi/nginx with 'block all connections without VPN' enabled. And this testing has been done from within the same LAN.

It should never see/reach cloudflare for this service.

/edit; I've also disabled 'use secure DNS' in chrome. I host a local DNS within that lan/vpn network.

 

In the last couple of weeks, I've started getting this error ~1/5 times when I try to open one of my own locally hosted services.

I've never used ECH, and have always explicitly restricted nginx to TLS1.2 which doesn't support it. Why am I suddenly getting this, why is it randomly erroring, then working just fine again 2min later, and how can I prevent it altogether? Is anyone else experiencing this?

I'm primarily noticing it with Ombi. I'm also mainly using Chrome Android for this. But, checking just now; DuckDuckGo loads the page just fine everytime, and Firefox is flat out refusing to load it at all.

Firefox refuses to show the cert it claims is invalid, and 'accept and continue' just re-loads this error page. Chrome will show the cert; and it's the correct, valid cert from LE.

There's 20+ services going through the same nginx proxy, all using the same wildcard cert and identical ssl configurations; but Ombi is the only one suddenly giving me this issue regularly.

The vast majority of my services are accessed via lan/vpn; I don't need or want ECH, though I'd like to keep a basic https setup at least.

[–] Darkassassin07@lemmy.ca 1 points 4 hours ago

You've done enough, keeping it behind your routers firewall.

You could block LAN access and require a VPN connection to that specific machine if you really wanted more, but I'm not that concerned about it.

[–] Darkassassin07@lemmy.ca 2 points 5 hours ago* (last edited 5 hours ago) (2 children)

Yup. Point is; if you're not depending on just its login page to keep it secure, there's not a whole lot needing 'security patches', so I wouldn't be all that concerned about slow updates. As long as it remains bug free, I'm happy.

[–] Darkassassin07@lemmy.ca 10 points 7 hours ago* (last edited 7 hours ago) (1 children)

I'm always a bit put off when she shows off her dick.

[–] Darkassassin07@lemmy.ca 40 points 9 hours ago (4 children)

But, look at that perspective shot; that thing is HUGE! You definitely want to sleep with me now right? Right??

[–] Darkassassin07@lemmy.ca 2 points 22 hours ago (4 children)

And security patches

Something with the power of dockge should be behind a seprate form of authentication imo.

I only access it via VPN, it's not exposed to WAN.

 

I've been using paperless-ngx to consume mail from outlook/hotmail for a while now, but recently had the mail server refuse connections while mail was being processed. (Not sure why, consuming is working now with no changes and no errors besides 'connection refused', while retrieving that mail. Temporary outage I guess?)

This left me with a couple pieces of mail not imported. However, now everytime the mail consume task runs, it recognizes that those pieces of mail are there but refuses to process them with the message:

Skipping mail '421' '<email subject>' from '<sender email>', already processed.

How can I get it to recognize those mails HAVE NOT been processed?

 

Aug 13 (Reuters) - General Motors (GM.N), has been sued by the state of Texas, which accused the automaker of installing technology on more than 14 million vehicles to collect data about drivers, which it then sold to insurers and other companies without drivers' consent.

15
submitted 3 months ago* (last edited 2 months ago) by Darkassassin07@lemmy.ca to c/jerboa@lemmy.ml
 

I've noticed with the last 2-3 versions of the app (currently 0.0.69, nice); the app crashes 2/3rds of the time when returning to it from being in the background.

Open the app, switch to another app, switch back a couple min later and it closes then reopens as if you'd just started it for the first time today (losing whatever post you had open).

Curious if others are experiencing this?

Android 14, One UI 6.1

 
 

All ~~roads~~ videos lead here:

Honestly I'm surprised it took this long. The only other issue I've ever seen (between revanced and the original vanced app) is the watch history not saving a couple weeks back.

 

When a file is manually replaced, for example after converting from an mp4 to an mkv; radarr decides to delete everything in that movies folder: posters, backdrops, subtitles, NFO files, leaving only the new video file; even though none of these were created or managed by Radarr ever.

This causes Emby to have to rescan/reidentify the item, re-downloading all the extra data, and it's now lost all custom metadata that was stored in the nfo, particularly the original date added to emby and it now has no subtitles.

How can I prevent this?

 

I've started noticing this icon more and more: usually on comments with no downvotes. What's it mean?

 

CPU/GPU/RAM/Disk usage, logs, errors, network usage, overall status, etc

What do you use/prefer?

Mainly looking for self-hosted web based tools, stuff I can view from a browser; but desktop and CLI apps are welcome too :)

 

I have what may be a stupid question...

How is it your master password is both used to decrypt your vault and used to authenticate with bitwardens public servers to acquire a copy of your vault/view it in the web app, but bitwarden can't use that password entry to decrypt the vault themselves?

(please correct me if I'm misunderstanding, as I use self-hosted vaultwarden for my server instead of the public ones)

87
submitted 8 months ago* (last edited 8 months ago) by Darkassassin07@lemmy.ca to c/selfhosted@lemmy.world
 

After almost a year of repeated emails stating the transition from Google Domains will have no effect on customers, no action is required; I just got this email:

Update Dynamic DNS records Hi there, As previously communicated, Squarespace has purchased all domain name registrations and related customer accounts from Google Domains. Customers are in the process of being moved to Squarespace Domains, but before we migrate your domain [redacted] we wanted to inform you that a feature you use, Dynamic DNS (DDNS), will not be supported by Squarespace.

So apparently SquareSpace will be entirely useless to me and I've got "as soon as 30 days" to move.

Got any suggestions for good registrars to migrate to?

(it's a .pw domain if that matters)

/edit. I'm a moron.

I already use cloudflare as my name server, Google/SquareSpace only handles the registration.

I'll be fine. Thanks for the help everyone!

1
submitted 9 months ago* (last edited 9 months ago) by Darkassassin07@lemmy.ca to c/main@selfhosted.forum
 

-post won't delete, so redacted instead-

view more: next ›