setup SSL/TLS encryption HELP from DNS bought from cloudflare

I want to setup my website soon. I noticed that my SSL is not setup automatically. Can someone help me ?
85 Replies
Maggie in CA
Maggie in CA2mo ago
@CosmosisT Under Attack Mode is active :NotLikeThis:
CosmosisT
CosmosisT2mo ago
Where are you stuck? This is not really specific, have you tried anything?
Maggie in CA
Maggie in CA2mo ago
I think i need to set the SSL/TLS up I dont know how to. I don't know I maybe encountering a bug?
Maggie in CA
Maggie in CA2mo ago
@CosmosisT
No description
Maggie in CA
Maggie in CA2mo ago
@CosmosisT
No description
CosmosisT
CosmosisT2mo ago
Oh no bug, just setting up essentially. So have you generated your SSL with CloudFlare for *.agileathena.com/ I couldn't add another * (discord code is weird)
Maggie in CA
Maggie in CA2mo ago
yes. It is not secure tho
CosmosisT
CosmosisT2mo ago
Do you have the files for the SSL (don't share them).
Maggie in CA
Maggie in CA2mo ago
I dont know what that is Where do I get that? @CosmosisT
CosmosisT
CosmosisT2mo ago
Uh been a while since I collected mine but it's I believe through SSL>Origin Server You create a certificate and download your files and the server code you should set to run the certs over HTTPS. reject anything port 80 or HTTP.
Maggie in CA
Maggie in CA2mo ago
@CosmosisT This
CosmosisT
CosmosisT2mo ago
Yeah That looks right
Maggie in CA
Maggie in CA2mo ago
Can i sent you a Pvt DM?
CosmosisT
CosmosisT2mo ago
Now this leads to sensitive data; do save everything cause some things may be needed still but don't share too much of that. You can but good practice is never do that again, I don't personally want cert access/etc or anything malicious to do with sites. But so you know you should learn this process on your own!!!!!!!!!!!
Maggie in CA
Maggie in CA2mo ago
I just want to prepare this. I thought it is automatic!
CosmosisT
CosmosisT2mo ago
No no Cause you'll gain files that help with the cypher/encryption process So youre servers will need these certificates
Maggie in CA
Maggie in CA2mo ago
This will applly to all my sub-websites?
CosmosisT
CosmosisT2mo ago
It's a secret/secure method for encrypting traffic, so yeah we need to do this process and get use to doing it yearly in some cases with CF they have a layered method so they'll switch the SSL mid-layer. The SSL will apply to anything you have proxied in DNS. So if it's under cloudflare protection it'll work.
Maggie in CA
Maggie in CA2mo ago
is it in developers documentation?
CosmosisT
CosmosisT2mo ago
I'm sure it is When you turn off CF proxy in DNS for a record it's on you to provide an SSL/etc. Otherwise if proxy is on with DNS records they all can use the certificate as long as they operate on the ports/protocals they allow.
Maggie in CA
Maggie in CA2mo ago
How long is the process for this to get activated?
CosmosisT
CosmosisT2mo ago
Immediate generally.
Maggie in CA
Maggie in CA2mo ago
Can you walk pls me through?
CosmosisT
CosmosisT2mo ago
But that's given you know how to setup so possibly 2 hours tops?
Maggie in CA
Maggie in CA2mo ago
with you? I doubt it
CosmosisT
CosmosisT2mo ago
Well the domain server, or the main server do you have abiliity to set HTTPS Not sure your setup but can you easily set HTTPS and set the certificates?
Maggie in CA
Maggie in CA2mo ago
Nope, but it seems like it is done step by step I haven't done that before
CosmosisT
CosmosisT2mo ago
Hmm, what kind of service are you using to host the server?
Maggie in CA
Maggie in CA2mo ago
WEbsite first to SaaS
CosmosisT
CosmosisT2mo ago
To clear this, your domain it's established or configured with cloudflare? The name servers are set and all sorts properly?
Maggie in CA
Maggie in CA2mo ago
no because I bought this directly from cloudflare. Namecheap has that defined
CosmosisT
CosmosisT2mo ago
Not sure if you bought domain with cloudflare but getting an idea of the setup. Okay so domain is bought with CF so it should be defaulted. that's one step out of the way, so your actual server hosting the services does it have a control panel or root acess?
Maggie in CA
Maggie in CA2mo ago
Did you mean this ...
No description
CosmosisT
CosmosisT2mo ago
Perhaps code you can modify?
Maggie in CA
Maggie in CA2mo ago
not sure
CosmosisT
CosmosisT2mo ago
yes
Maggie in CA
Maggie in CA2mo ago
I bought that site. It is active but not secured
CosmosisT
CosmosisT2mo ago
Do you have a server for it? A domain name is just a domain name.
Maggie in CA
Maggie in CA2mo ago
I dont have a server
CosmosisT
CosmosisT2mo ago
So you just have a domain name.
Maggie in CA
Maggie in CA2mo ago
yes Is it included?
CosmosisT
CosmosisT2mo ago
No no There are some free products you may use but ideally you may want to buy a server or a pre-managed service
Maggie in CA
Maggie in CA2mo ago
like from firebase, etc?
CosmosisT
CosmosisT2mo ago
Many o ptions What are you trying to host?
Maggie in CA
Maggie in CA2mo ago
Where do you recommend?
CosmosisT
CosmosisT2mo ago
A domain name is a great start, but now need to consider servers or a service you can route with your sites DNS now. Well I need to know what you plan to host to recommend.
Maggie in CA
Maggie in CA2mo ago
A microservice like Netflix style but not videos but documents like templates to sell Im thinking shall I do it directly as SaaS or website first
CosmosisT
CosmosisT2mo ago
You should tinker around with what works to learn the basis You've seen wordpress sites, does that work?
Maggie in CA
Maggie in CA2mo ago
I had this www.savvymedipedia.com
CosmosisT
CosmosisT2mo ago
Just need to learn a bit of CPanel for a little bit till you can go a bit crazy with development.
Maggie in CA
Maggie in CA2mo ago
i created this www.savvymedipedia.com
CosmosisT
CosmosisT2mo ago
So you should know then how to generate SSL, apply it to your HTTPS service.
Maggie in CA
Maggie in CA2mo ago
I used netlify They do that for me
CosmosisT
CosmosisT2mo ago
Those are managed services they make it easy so for you, you need to find a service that can let you do that and you get a direct IP. This however may require some know how... :X
Maggie in CA
Maggie in CA2mo ago
what should I learn? Maybe i just use manage services then 😦
CosmosisT
CosmosisT2mo ago
Well for the server part it depends, you can get a server with full terminal/root access and have to set everything up yourself and if confused can be compromised. You can get a managed service that should be able to provide direct IP and as well secure this for a safe/secure wordpress setup.
Maggie in CA
Maggie in CA2mo ago
Which cloudflare does can i easily transfer my code from wordpress to saas?
CosmosisT
CosmosisT2mo ago
That's a different question, I wouldn't know fully CF gots tons of products.
Maggie in CA
Maggie in CA2mo ago
They have a lot Oh gosh. what do i do now with this domain name
CosmosisT
CosmosisT2mo ago
Open new topics and google for that, your SSL though generate it and save all information/files. you can do tons; you bought it for a reason.
Maggie in CA
Maggie in CA2mo ago
Im happy but how ? It sounds complicated
Maggie in CA
Maggie in CA2mo ago
Cloudflare Docs
Secure your origin · Getting started · Learning paths
Your origin server is a physical or virtual machine that is not owned by Cloudflare and hosts your application content (data, webpages, etc.).
Maggie in CA
Maggie in CA2mo ago
I have a knowledge gap from this
No description
Maggie in CA
Maggie in CA2mo ago
Adding domain to CF is easy
CosmosisT
CosmosisT2mo ago
Your domain is on CF already it's ready; the DNS is awaiting records to work with your server. Issue is you don't have a server running just yet. So you just need a managed server that you can change certs and do simple stuff. Nothing to insane
Maggie in CA
Maggie in CA2mo ago
I see. Great points. Thank you 🙏🏻🙏🏻
CosmosisT
CosmosisT2mo ago
You'll get an IP to the server, you set an A record if IPv4 or AAAA if IPv6 and send domain to that address via proxy and have that server use the certs you gen with cloudflare and enjoy. I am heading out for a while I hope you sort it. CF may offer free services you can link DNS to I'm not entirely sure.
Maggie in CA
Maggie in CA2mo ago
Thank you so much. NAmecheap has that for me. Why not CF? 😦 Have a good day!
CosmosisT
CosmosisT2mo ago
I use namecheap as a domain name, just have it linked to CF. I assume you may be able to link their product same way.
Maggie in CA
Maggie in CA2mo ago
I see. Shall I buy another one? Buy it from namecheap then CF?
CosmosisT
CosmosisT2mo ago
Ask more questions and figure it out. I am old-school, I buy VPS and cloud computing galore.
Maggie in CA
Maggie in CA2mo ago
I see. ok. That's helpful still CF is an augment to you
CosmosisT
CosmosisT2mo ago
You just need to be able to safely assign a DNS record to the server and the server hosting the certs.
Maggie in CA
Maggie in CA2mo ago
Did you see their workers AI?
CosmosisT
CosmosisT2mo ago
It's a firewall for me which requires the SSL.
Maggie in CA
Maggie in CA2mo ago
I hope not a long process
CosmosisT
CosmosisT2mo ago
I don't use much more of the products, I need high demand applications.
Maggie in CA
Maggie in CA2mo ago
Like?
CosmosisT
CosmosisT2mo ago
I have to design my own gateways and all sorts and custom CDNs.
Maggie in CA
Maggie in CA2mo ago
Cool Are you in cybersecuirity?
CosmosisT
CosmosisT2mo ago
But the process for you is very quick if you have what you need but learning process is a bit much. You just need a server now that supports you using your own SSL/etc, all the fun. Provides IP to set an A, or AAAA record. lol. Anyways have a fun day, I hope you sort things do ask more questions. I must step away for a bit.
Maggie in CA
Maggie in CA2mo ago
OK, take care. What is funny to be in Cybersecurity?
CosmosisT
CosmosisT2mo ago
Oh nothing, it's just much more than that. But not that uh, "fancy". Full-stack developer but security was taught day one.
Maggie in CA
Maggie in CA2mo ago
Where? where? yeah but it is important. How do you see security in DevOpsSec using ReactJS stack? ? I got a 403 code from stumblechat 😦
CosmosisT
CosmosisT2mo ago
Anything can be compromised if code is slightly wrong. I have to tend to stuff so GL. Stumble is strict.