Skip Navigation
having trouble with NGINX Mgr and SSL

I'm pretty new in this space, and have been tinkering around with some self-hosting for the last month or so, via Docker on an Ubuntu host. I'm pretty comfortable with Linux, but trying to learn reverse-proxy stuff. So, I thought my next project would be Vaultwarden, but I want to be able to access it from outside the network, and I need SSL working. I have gotten other dockers to be accessible from outside (http://bookstack.oaf.monster) using nginx manager, but the two I've tried with SSL (vik.oaf.monster and vault.oaf.monster) give me 502 Bad Gateway errors. So I know I'm configuring something incorrectly. Been trying to fix this as I've had time for the last week, and finally deciding I need to reach out for help! Any notes/tips/ideas are appreciated.

First and foremost, here's what I see in the error log for nginx:

2023/08/21 16:54:29 [error] 3049756#3049756: *95695 SSL_do_handshake() failed (SSL: error:1408F10B:SSL routines:ssl3_get_record:wrong version number) while SSL handshaking to upstream, client: 10.23.0.32, server: vault.oaf.monster, request: "GET / HTTP/2.0", upstream: "https://10.23.0.220:8006/", host: "vault.oaf.monster" 2023/08/21 16:54:29 [error] 3049756#3049756: *95695 SSL_do_handshake() failed (SSL: error:1408F10B:SSL routines:ssl3_get_record:wrong version number) while SSL handshaking to upstream, client: 10.23.0.32, server: vault.oaf.monster, request: "GET /favicon.ico HTTP/2.0", upstream: "https://10.23.0.220:8006/favicon.ico", host: "vault.oaf.monster", referrer: "https://vault.oaf.monster/"

I see it says wrong version number, but admittedly I have no idea what to do with that. Not experienced enough in SSL.

My NGINX config file for vaultwarden (I know how to use cat, but I don't know how to manually edit this file if I need to... no vi on the docker!):

``` [root@docker-bf5d51784409:/data/nginx/proxy_host]# cat 7.conf

------------------------------------------------------------

vault.oaf.monster

------------------------------------------------------------

server { set $forward_scheme https; set $server "10.23.0.220"; set $port 8006;

listen 80; listen [::]:80;

listen 443 ssl http2; listen [::]:443 ssl http2;

server_name vault.oaf.monster;

Let's Encrypt SSL

include conf.d/include/letsencrypt-acme-challenge.conf; include conf.d/include/ssl-ciphers.conf; ssl_certificate /etc/letsencrypt/live/npm-4/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/npm-4/privkey.pem;

# Force SSL include conf.d/include/force-ssl.conf;

access_log /data/logs/proxy-host-7_access.log proxy; error_log /data/logs/proxy-host-7_error.log warn;

location / { # Proxy! include conf.d/include/proxy.conf; }

Custom

include /data/nginx/custom/server_proxy[.]conf; } ```

This is my docker-compose for vaultwarden, in case it's relevant:

``` version: '3'

services: vaultwarden: image: vaultwarden/server:latest container_name: vaultwarden restart: unless-stopped environment: DOMAIN: "https://vault.oaf.monster" # Your domain; vaultwarden needs to know it's https to work properly with attachments volumes: - ./vw-data:/data ports: - 8006:80 ```

And lastly, I took a few screenshots and put them here... might be useful. https://imgur.com/a/JRH9jXi

What am I doing wrong? I'm open to the idea that it might be multiple things. Thanks in advance!

2
Rant: Frustration Related to Ethics of Games Companies
  • Larian studios seems great. I would like more companies to invest in / hire studios similar to Larian. Sure, WotC sucks. But I will vote with my dollars for them to work with Larian. Maybe it means in the future more gaming companies might look like Larian. Everybody has to draw their own line, though.

  • Games on GOG?

    Hello! I'm looking for any game recommendations on GOG -- especially anything that's on sale! Tell me about your favorite few games that you have on GOG, or maybe some gems in the rough out there. I've seen a few threads on Steam lately, so it feels appropriate to me to look for some love on one of the smaller game systems. I'll mention a couple of my favorites, but feel free to mention anything you like!

    Rimworld - An alien-planet civilization sim kind of game. I've gotten many hours out of this one. And with some mods and DLC... oh man. I might be ashamed to see how many hours I've played it.

    Northgard - I think you'd call this an RTS. Super rad, wish it was longer. I'll swing back around and re-play the whole campaign sometime. I just now noticed they have an expansion pack, so maybe I'll get that soon.

    Sid Meier's Railroads - Railroad sim. Another one that I've dumped a ridiculous number of hours into.

    Faster Than Light (FTL) - rogue-like spaceship game?! I don't know how to describe it, but I loved it.

    I also recently picked up Starship Troopers: Terran Command and Graveyard Keeper, but haven't taken the time to play them, yet. I have Stardew Valley on GOG -- Not an all-time favorite, but definitely got my money's worth and had fun with it.

    A few I've had my eye on but would love to hear outside opinions: Patron, Space Crew, Mars Base. They look interesting, and probably any little nudge would get me to buy and try.

    25
    Looking for Long-Term Games
  • Satisfactory is so good. One of my all-time favorites. I use a dedicated server when I play it, because I'll play from a few different computers when I do. But resources stop pumping out if nobody is connected to it. Maybe there's an option or a setting to keep things rolling, but that's the default behavior -- nobody connected the game effectively pauses.

  • Looking for tech documentation solution

    So I'm on the lookout for something, but I don't know how to briefly describe it. I want something to help me document various projects at work. It's not uncommon for me to spend a week setting something up, and it works for 2 years and then has a problem -- and I have to re-learn everything about it from the ground up before I can start solving it. For example, I'm setting up a new VMWare server today, and I just know I'm going to forget some of the details on it -- so I want to be able to type out some of the specs and processes, maybe use some tags, a coupel hyperlinks to more info, and be able to search for it a year from now. Does that make sense? Anybody have any suggestions?

    6
    What are some of the best games you can self-host a server for?
  • These are ones I keep coming back to: Farming Simulator, Satisfactory, and Valheim. I've also kept up a V-Rising server at times because my friends like it, but I'm not as into that game. Always on the lookout for games to host for friends, so I'm glad I stumbled upon this thread! Found a few in here I'm going to try out.

  • AVClub: What went wrong with Elemental—and where does Pixar go from here?
  • I don't get it. Took my daughter today and we both loved the movie. The story was good, characters were good, had some jokes we both laughed at. I got choked up a few times near the end (I'm a softie, not abnormal for me), and the animation was outstanding. Beautiful movie to look at. My daughter (9) also loved it, said on the way out that she hoped they'd do a sequel. I do feel like the advertising didn't do a great job of telling me what the movie would be about, though. There was a lot more to it than just a young romance. Thumbs up for me overall.

  • InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)PL
    plasticus @beehaw.org
    Posts 3
    Comments 7