AdguardTeam / AdguardTeam/AdGuardHome

DNS related: ssl/tls SSL_ERROR_BAD_CERT_DOMAIN

Open
#7,525 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
36.9k
Forks
2.5k
PR merge metrics
No merged PRs in 30d

Description

### Prerequisites

- [X] I have checked the [Wiki](https://github.com/AdguardTeam/AdGuardHome/wiki) and [Discussions](https://github.com/AdguardTeam/AdGuardHome/discussions/categories/q-a) and found no answer

- [X] I have searched other issues and found no duplicates

- [X] I want to report a bug and not [ask a question or ask for help](https://github.com/AdguardTeam/AdGuardHome/discussions/categories/q-a)

- [X] I have set up AdGuard Home correctly and [configured clients to use it](https://github.com/AdguardTeam/AdGuardHome/wiki/Clients). (Use the [Discussions](https://github.com/AdguardTeam/AdGuardHome/discussions/categories/q-a) for help with installing and configuring clients.)

### Platform (OS and CPU architecture)

FreeBSD, AMD64 (aka x86_64)

### Installation

GitHub releases or script from README

### Setup

Other (please mention in the description)

### AdGuard Home version

107.55

### Action

Every so often we'll get a invalid ssl cert for a domain name that we know is good. An immediate reload fixes the problem.
Mostly it happens with domains related to AWS root certificates. I have always related it to something with ChromeOS/Browser and Google Workspace. As AWS Root Cert is in Windows and ChromeOS Base..

Today while using ZenBrowser on a Windows PC and very low traffic I experienced the same and found that AGH gave me dns entries from Quad9 which I cannot get from Quad9 again, or via a dns looking glass, which do not belong to the zone reached via recursion.


![image](https://github.com/user-attachments/assets/9259b4cf-cc7e-4a1c-856d-0c7a23e8a533)

Note that all the IPs are different from the looking glass (which was done for the purpose of this issue..)

http://www.dns-lg.com/us01/store.ui.com/a

![image](https://github.com/user-attachments/assets/a9f17599-068e-44cb-92b2-8428d7b59ff2)

This is from a cli program called `q` (github.com/natesales/q)
![image](https://github.com/user-attachments/assets/8ad93a88-2e87-477d-9435-ce1d69cfab04)

As quickly as I could open a term and type.. (less than two minutes of the initial problem)

As you can see 34.213.96.150 and 44.241.198.88 and 54.187.135.47 were never returned as valid records.

(none of those do not answer https) BUT

52.36.140.184 Is the *.clarifyhealth.us, clarifyhealth.us host.. (not store.ui.com)

Using this dnsstamp for the doh entry: (from dnscrypt-proxy2 v3 list..)
sdns://AgIAAAAAAAAABzkuOS45LjkgsBkgdEu7dsmrBT4B4Ht-BQ5HPSD3n3vqQ1-v5DydJC8TZG5zOS5xdWFkOS5uZXQ6NTA1MwovZG5zLXF1ZXJ5

My AGH host is FreeBSD on baremetal

My AGH Bootstrap is also a dnsstamp for dnscrypt:
sdns://AQMAAAAAAAAAFDE0OS4xMTIuMTEyLjExMjo4NDQzIGfIR7jIdYzRICRVQ751Z0bfNN8dhMALjEcDaN-CHYY-GTIuZG5zY3J5cHQtY2VydC5xdWFkOS5uZXQ

Bootstrap has DNSSEC doh dnsstamp does not.. (I cannot think that someone mitm my one dns request for store.ui.com - just to put that out there..)

![image](https://github.com/user-attachments/assets/b76604ce-87f9-4d45-a7f7-5c96cc66fdc3)

![image](https://github.com/user-attachments/assets/36c98904-07e1-4929-b73b-5992ded5f80d)

https://osint.sh/crt/ shows *many* certs for the domain..

but

https://osint.sh/dns/ shows *nothing* for the domain.. just NS records..

asking those NS's also yields no records..

(very strange)

Everything related to dns/doh/'https only mode'/etc was already disabled in Zen..

```
OS Name: Microsoft Windows 10 Pro Education
OS Version: 10.0.19045 N/A Build 19045
```

### Expected result

The A records which appear to be in the zone file as visible from other recursive clients.

### Actual result

Not the vendor supplied A records

### Additional information and/or screenshots

FreeBSD

```
/usr/local/bin/adguardhome --version
AdGuard Home, version v0.107.55
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.