mirror of
https://github.com/netbirdio/docs.git
synced 2026-09-28 17:59:05 +02:00
Document TLS-ALPN-01 challenge requirements for reverse proxy (#656)
This commit is contained in:
@@ -422,6 +422,10 @@ If your self-hosted deployment currently uses Nginx, Caddy, or another reverse p
|
||||
2. Ensure the wildcard DNS record resolves correctly: `dig myapp.proxy.example.com`
|
||||
3. Check proxy logs for ACME errors: `docker compose logs proxy | grep -i acme`
|
||||
4. If using `http-01` challenge type, ensure port 80 is also accessible
|
||||
5. Ensure no geo-blocking is active on your firewall or CDN - Let's Encrypt validates from multiple global locations simultaneously, and blocking non-local IPs will cause validation to fail
|
||||
6. If you have an additional proxy or load balancer in front of Traefik, verify it supports the `acme-tls/1` ALPN protocol required by the `tls-alpn-01` challenge. Some providers (such as Cloudflare) may not pass through this protocol. If this is an issue, switch to `NB_PROXY_ACME_CHALLENGE_TYPE=http-01`
|
||||
|
||||
For a full explanation of TLS-ALPN-01 requirements, see [TLS-ALPN-01 requirements](/manage/reverse-proxy#tls-alpn-01-requirements).
|
||||
|
||||
### TLS passthrough not working
|
||||
|
||||
|
||||
Reference in New Issue
Block a user