GuidesCustom domains & HTTPS
Problems with a custom domain
Most problems have one of two causes: the DNS, or port 80.
DNS. The domain resolves to this server.
1 / 4
| What you see | What to check |
|---|---|
ferry certificates shows failed | The cause is next to the state, with the time of the next attempt. |
No requesting a TLS certificate line in the log | HTTPS is off. ferry info shows TLS: disabled until ferryd has --https-addr and --acme-email. |
| The request fails in the log, and Ferry tries again later | The DNS, or port 80. See the list below. |
| Rate limits of Let’s Encrypt | Test with --acme-staging. |
404 with x-ferry-error: not_found | No service on this server has the domain. Run ferry domains shop. |
The app builds http:// links | Read the scheme from X-Forwarded-Proto. See Networking. |
The two frequent causes
- The domain does not resolve to this server.
- The internet cannot reach port 80: a firewall, a cloud security group, or another program on port 80.
After a failure, Ferry waits 5 minutes before the next attempt for that hostname. Then it waits 10 minutes, then 20, and so on, up to 6 hours. A restart of ferryd starts a new attempt immediately.
The certificates of the test system of Let's Encrypt have large limits, but browsers do not trust them. When you remove the option, Ferry replaces them with production certificates.
The proxy stops the TLS encryption and talks plain HTTP to your app. Thus the app must read the scheme from the header X-Forwarded-Proto.
A local name gets no certificate. Thus the log has no requesting a TLS certificate line for it.