Score:0

How does Digital Ocean App issue a certificate on my behalf?

fr flag

I am trying to understand how this works so that I can maintain it. I do not understand how my digital ocean app was able to automatically issue and serve a cloudflare edge certificate despite CF proxy disabled on that domain.

I have a basic network that consists of a few resources on DO and AWS with CloudFlare Proxy. CF is set to strict mode There are three hosts

A.example.com - A Record to AWS Server, Proxied, LetsEncrypt Certificate
B.example.com - CNAME Record to DO App, Not Proxied, **CF Edge Certificate**
C.example.com - CNAME Record to DO CDN, Not Proxied, LetsEncrypt Certificte

For Host A, everything is what I would expect. I use certbot with cf plugin to issue certificates directly on the host. When I turn off the proxy I see my host cert, when I turn on the proxy I see CF's edge cert.

For Host C, everything is what I would expect. I generate the certificate with certbot and upload the certificate and key to digital ocean. I could move my nameservers to digital ocean for them to manage this too but I have not yet. When I turn off the proxy I see my LE certificate

Host B is where I do not understand. I started an app with a static website. I added the domain to the app, I was expecting to have to provide a certificte but instead it appears to serve cloudflares edge certificate for my domain with strict mode enabled and proxy disabled.

What is going on here? I read somewhere the CF is providing certificate services for DO. Who is going to renew my certificate for B.example?

us flag
I guess you'd need to look into the chain of trust to see how they are doing that.
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.