Skip to content
View in the app

A better way to browse. Learn more.

Unraid

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

NPM-Official and browser SSL cert errors

Featured Replies

Hi I'm having a problem with SSL certs, on Firefox I'm getting SSL_ERROR_INTERNAL_ERROR_ALERT (with Chrome it's a ERR_SSL_PROTOCOL_ERROR) when navigating to my proxy host. Below are the setup steps I followed along with the troubleshooting I did. Short of testing the SSL cert on a webserver to verify that it is intact (please let me know if I should attempt this), I'm out of ideas. Any help is greatly appreciated.

The setup steps I followed:

  1. Setup a subdomain haos.mydomain.com to redirect to my top-level domain, mydomain.com

  2. Verify that mydomain.com is currently pointed to my dynamic IP (via dynamic DNS).

  3. Follow this tutorial to setup NPM-Official, which is basically:
    https://www.youtube.com/watch?v=nhacNUxVcy4

    1. Install NPM-Official container. Choose to have a fixed IP address.

    2. Forwarded ports 80 and 443 from my router to the NPM-Official IP address.

    3. Verify that I can access the NPM-Official welcome screen when navigating to http://myipaddress

    4. Setup mydomain.com and *.mydomain.com SSL Certs in the NPM webUI. I deviated from the tutorial by enabling DNS Challenge to allow wildcard cert generation.

    5. Create a Proxy Host. It's pointed to my HA OS virtual machine, so http and port 8123. It uses the *.mydomain.com SSL cert.

Now I should be able to type in haos.mydomain.com via http or https and see the HA OS interface. But instead, what I see with http is 502 bad gateway, and with https SSL_ERROR_INTERNAL_ERROR_ALERT on Firefox and with Chrome it's a ERR_SSL_PROTOCOL_ERROR.

Troubleshooting:

  • nslookup says haos.mydomain.com is correctly pointed to my external IP address

  • manually navigating to the HA OS IP address successfully shows me the HA web interface as expected

  • NPM-Official log shows successful cert generation when I click on Renew:

[7/5/2025] [8:40:19 PM] [SSL ] ›  info
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/npm-2.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Renewing an existing certificate for *.mydomain.com and mydomain.com
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Congratulations, all renewals succeeded: /etc/letsencrypt/live/npm-2/fullchain.pem (success)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
[7/5/2025] [8:40:19 PM] [Global ] › ⬤ debug CMD: openssl x509 -in /etc/letsencrypt/live/npm-2/fullchain.pem -subject -noout
[7/5/2025] [8:40:19 PM] [Global ] › ⬤ debug CMD: openssl x509 -in /etc/letsencrypt/live/npm-2/fullchain.pem -issuer -noout
[7/5/2025] [8:40:19 PM] [Global ] › ⬤ debug CMD: openssl x509 -in /etc/letsencrypt/live/npm-2/fullchain.pem -dates -noout

Edited by gusgus
formatting

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.