I’ve done some more digging and it seems like fly is still inserting itself between things.
From the deployed server;
openssl s_client -connect localhost:443
Returns a much different set of errors than running it from a local machine;
openssl s_client -connect test.domain.net:443
On the server I see;
CONNECTED(00000003)
Can't use SSL_get_servername
depth=0 O = "CloudFlare, Inc.", OU = CloudFlare Origin CA, CN = CloudFlare Origin Certificate
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 O = "CloudFlare, Inc.", OU = CloudFlare Origin CA, CN = CloudFlare Origin Certificate
verify error:num=21:unable to verify the first certificate
verify return:1
depth=0 O = "CloudFlare, Inc.", OU = CloudFlare Origin CA, CN = CloudFlare Origin Certificate
verify return:1
---
Certificate chain
0 s:O = "CloudFlare, Inc.", OU = CloudFlare Origin CA, CN = CloudFlare Origin Certificate
i:C = US, O = "CloudFlare, Inc.", OU = CloudFlare Origin SSL Certificate Authority, L = San Francisco, ST = California
---
Which I think makes sense, because I’m asking it to verify localhost when this is a cert for test.domain.net (I’m editing the actual domain being used of course)
When I run openssl locally and point it at fly, either pointing directly at the blah.fly.dev or pointing it at my correct subdomain (test.domain.net) I get;
CONNECTED(00000005)
8328020288:error:1404B42E:SSL routines:ST_CONNECT:tlsv1 alert protocol version:/AppleInternal/Library/BuildRoots/9e200cfa-7d96-11ed-886f-a23c4f261b56/Library/Caches/com.apple.xbs/Sources/libressl/libressl-3.3/ssl/tls13_lib.c:151:
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 5 bytes and written 294 bytes
I think this suggests that fly is doing something before the request even makes it to nginx.