XF 1.5 TLS1.2 + CloudFlare = fail?

CrispinP

Well-known member
Folks,

So in setting up my new forum using XF I noticed the your-server's-not-worthy banner in User Upgrades page.
After reading Mike's two threads and some others around I decided I might as well tick it off now and be done with it.

I've disabled TLS1.0, 1.1 on my server.

However, it seems that me using CloudFlare in the mix is a show-stopper (for their continued use)
My domain, https://www.landcruiserclub.net/community points to CF who then point on to me. Everything is encrypted from me to them (waste of money - I could have used an unsigned cert :( ) and from CF on to me is encrypted with their cert.

The problem is that CF is still allowing 1.0+ as confirmed by online ssl tester. If you want to use TLS1.2 only then you need to be on their business plan which is USD200 a month. Gulp.

I still see the banner in User Upgrades - I assume this is because it's querying the FQDN which is then going via CF.

Is my understanding of all this correct?

Thanks
Crispin
 
Oh, huh. Well that's strange, but it sounds like a technical issue with the former account. I have the controls available to me on a free domain:

wkR9sd1.png
 
Your library versions are similar to what we run here without the issue you're having, though we do have a newer version of PHP. I don't know why setting that CURLOPT_SSLVERSION value works, since as far as I understand, cURL doesn't actually know how to interpret it in the version in use on your server.

Would it be possible to get FTP access to attempt some debugging?

Sure, I'll set something up this evening when I am home and PM the details to you.

Regards,
Crispin
 
Just to update everyone in case someone else gets this - this has been solved by Mike. A new file was supplied which solved it. Guess it'll make it into a patch soon.

Great support.


Thanks
C
 
Top Bottom