Score:0

HTTPS traffic not working, but http traffic does

vu flag

I am running Microsoft Windows Server 2022 in an AWS EC2 instance with IIS running on it. I have an SSL certificate installed and bound to my website, but when I try to reach the website, it says that the connection has been reset.

The domain name is help.revonecompanies.com.

When I run the domain through whatsmydns.net it verifies the correct information and that it propagates to the right IP address. I also ran my ssl certificate through ssl shopper and it came back good on that end.

I have Wireshark installed and ran and it gives me a TCP retransmission when it tries to do the handshake. I am not 100% what that is or what I should be looking for in Wireshark.

I am not sure which setting I changed, but now I am getting a connection was reset from inside of the server and a can't reach this page from the client.

Running a curl cmd results in a "Could not resolve host" error.

The security group for the AWS Instance allows all http and https traffic.

I will attach the server logs below, as I am not really sure what I am looking at for that. Server Logs

I should also probably mention that it is a subdomain of revonecompanies.com and the dns is routed to the public IP of the web server hosting help.revonecompanies.com.

Here is a curl for https traffic: Curl Error

Screenshot of what my IIS manager looks like: IIS Manager

Advanced settings of website: Advanced Settings

I tested this against SSL Labs and got an A, but still at a loss as to why this is not connecting the way it should.

My AWS security group settings are open to all http and https traffic.

Rino Bino avatar
us flag
"connection has been reset" is probably the error you saw on the **client** side. What do the **server** logs tell you when the error throws? That error is typically not going to throw if there is an issue with the certificate itself, moreso an issue with how the server is handling the connection attempt.... you will really need to analyze the server logs to see what it's failing on.
Tim avatar
gp flag
Tim
Please edit your question to include the domain name. There's not enough information to help you in the question. Please also include any results of curl, ssh validating the certificate against the domain, and any other diagnostics you do. You should include some information about your AWS configuration, such as whether you have opened port 443 in the security group. You may find using an ALB with an AWS Certificate Manager provided certificate simpler, though an ALB has a cost.
Lex Li avatar
vn flag
It seems to work fine now. Maybe just a temp error due to DNS propagation.
Billy Cox avatar
vu flag
@LexLi Can you show me what screen you get? I can't access it on any client both inside and outside of my network.
Lex Li avatar
vn flag
Deleted the answer (as it's not an actual answer). The certificate has been properly set up, but your server probably isn't fully. You need to edit the question to include a diagram on your entire setup (anything other than the VM itself), and possibly an SSL Diag report, https://docs.jexusmanager.com/tutorials/ssl-diagnostics.html
Billy Cox avatar
vu flag
@LexLi provided a screenshot of my IIS manager. Not sure what else you might need.
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.