Thank you sir! I will add that to my stops as I try to figure this out.
Good comment overall but their galco domain looks behind some CDN but not Cloudflare so more than one such system may be involved. motorsandcontrol.com definitely is Cloudflare as I also noted earlier
* Some CDN but Cloudflare?
curl -I http://galco.com
HTTP/1.1 301 Moved Permanently
Location: https://galco.com/
Accept-Ranges: bytes
Date: Thu, 09 Nov 2023 18:24:56 GMT
X-Served-By: cache-iad-kjyo7100039-IAD
X-Cache: HIT
X-Cache-Hits: 0
X-Timer: S1699554296.388514,VS0,VE0
Vary:
Strict-Transport-Security: max-age=31557600
* Very clearly Cloudflare
curl -I http://motorsandcontrol.com
HTTP/1.1 301 Moved Permanently
Location: https://motorsandcontrol.com/
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 823818aaad733b84-IAD
You're 100% right. Thanks for the correction.
I still had a tab open and ran the wrong queries. Damn COVID brain. I was just going by dig and checking ARIN allocations for the results (via https://whois.arin.net/ which is so useful for stuff like this)– the IPs for that domain are all allocated to Fastly, not Cloudflare. I think we wrote our above responses at the same time, I'm just super-slow today and multi-tasking is not working well. I would not have chimed in on this had I seen your excellent comment above.
No worries. Works out better for @tthomas because now they know another thread to unravel (Fastly).
Hi @tthomas we have already chatted via the Certify The Web support helpdesk and your servers are running Certify Certificate Manager, you need to remote onto the servers and look at what the app says, but the problem you reported to me is probably a firewall blocking port 80 or cloudflare etc is not allow http port 80 traffic through to your servers.
I'd advise you to engage a technician to investigate this on your behalf as I get the feeling you don't have time to look at this in the required detail yourself. It's fairly straightforward if you have already gotten a certificate before.
If you are using cloudflare for domains note that you also have the option of using DNS validation instead of http validation: