New here, but I’ve used Let’s Encrypt for a while.
I have a Digital Ocean droplet with Debian 9 / Nginx, and I used certbot to create an SSL certificate for one of my website.
The certificate is working fine on my side and on every device. It’s doing fine on SSLlabs too. But a friend of mine tells me that it’s not working for him. He lives in Russia. He ran some tests and it’s giving those results:
Safari / Chrome, home connexion, no VPN: not working
Chrome, home connexion, no VPN, private mode: not working
Chrome, 4G connexion, no VPN: not working
Safari / Chrome, home connexion, using a VPN with a russian proxy: not working
Safari / Chrome, using a VPN with a german proxy: working fine
Safari / Chrome, using a VPN with a french proxy: working fine
Safari / Chrome, 4G connexion, using a VPN with a russian proxy: not working
Safari / Chrome, 4G connexion, using a VPN with a french proxy: working fine
I coulnd’t retrive the full infos of the “not working” situation. Depending of the browser, it’s just saying that the website is not safe, with the red lock and all. My friend can see the other websites where I’ve used certbot just fine.
The PC is quite new. And he have the same problem on his cellphone, using a 4G connexion. So I guess it's the russian government that is blocking. I have no idea why yet since the website is not even launched.
The site IP belongs to one of Digital Ocean, Inc subnets which is blocked by RKN, so the problem occurs when ISP redirects blocked ip to some block-info page, and of course certificate for this site in that case is not valid for this domain.