Good morning, I am also getting SSL certificate errors on my server. Are you able to assist please?
Hello,
I have this error :
Oct 13, 2021 13:26:22.579 [0x7f43df25ab38] DEBUG - CERT: incomplete TLS handshake from XX.XX.XX.XX:1056: sslv3 alert certificate unknown
Can you help me ?
Thank you
Hi Chuck- am getting errors on both WHSSERVER and papabear. Again-many thanks!
Have you restarted everything (including the players)?
your certificate is new:
Valid Wed, 13 Oct 2021 07:55:52 +0000 Wed, 13 Oct 2021 07:56:31 +0000
If Rasplex – Please see their GitHub
I have reset your certificate. You may restart the server.
I have removed the orphaned duplicate papabear (which had expired cert)
I have reset the other two servers.
You may restart both servers.
The “Collin’s Cloud” server. Thanks!
i last restarted Monday 10/11/21 after a server upgrade when all this trouble began
I removed all servers from authenticated devices list, then reclaimed to only show one server. I still cant externally connect securely since then. I do NOT want to allow insecure connections externally.
Thanks
@ChuckPa Thanks this is the error I receive at the time, would you happen to know what would cause this?
CERT: incomplete TLS handshake: tlsv1 alert unknown ca
Thank you
Perfect ! It’s work ! Thank you
Full logs please? I need see the context. I know it’s not the server certificate
I need to see the logs please which capture it attempting to connect remotely.
It could be anything from ports to firewall to throttled to bouncing a bad check 
is there a way to reset my cert on Plexifer? im at a loss. I had issues i uninstalled and tried to reinstall on a synology nas 1019+. it said unable to perform operation, log into dsm and try again later. I some how got my server back sort of but now there are two plexifers and the people i share with can not access the good one. any help would be great.
You did indeed have a mess there:
https://acme-v02.api.letsencrypt.org/acme/order// Valid Tue, 12 Oct 2021 16:40:53 +0000 Tue, 12 Oct 2021 16:41:32 +0000
https://acme-v02.api.letsencrypt.org/acme/order// Valid Wed, 13 Oct 2021 06:43:42 +0000 Wed, 13 Oct 2021 06:43:59 +0000
https://acme-v02.api.letsencrypt.org/acme/order// Valid Wed, 13 Oct 2021 16:12:02 +0000 Wed, 13 Oct 2021 16:13:01 +0000
I’ve removed it all.
Restart the server
I think on reflection it’s not a SSL issue - thanks for looking into though!
Hello
I believe I’m also experiencing this error:
Oct 13, 2021 18:20:29.897 [0x146e9d156b38] Debug — CERT: incomplete TLS handshake from XX.XXX.XXX.X:61786: sslv3 alert certificate unknown
Would you be able to reset my certificate as well?
I’m having issues with certain devices not being able to reach my server (3 mac computers and multiple ipads) while others (apple tv, iphones, surface laptop, roku etc) have no issue at all. I had been using default remote access options (for over a year) with no issues but when I started having trouble (more than a week ago), I changed to a manual port forward which did not fix my issue. My problem seems to be with getting a secure connection, so I’m not certain this is right forum. I have double checked that the mac computer can ping the server with no issue so it’s not a network issue. Obviously I also have my server set to the default setting for Secure connections - Preferred but not required. Can you please check/and or reset my certificate to see whether that is causing my issue or give me some further advice on what to look at next? I do not see a certificate error in my logs, but I’m not an expert at all at looking through these logs. The only thing that seemed like maybe it was relevant in the log that said “Plex token=redacted”.
sorry for the delay
will this suffice?
Oct 13, 2021 20:23:54.253 [0x7f5698128b38] Debug — Request: [192.168.1.217:42488 (Subnet)] GET /:/websockets/notifications?filters=log (16 live) GZIP Signed-in Token (FLUDzilla)
Oct 13, 2021 20:23:54.253 [0x7f5698128b38] Debug — WebSocket: Performing handshake from origin http://192.168.1.11:32400
Oct 13, 2021 20:23:54.253 [0x7f5698128b38] Debug — Beginning read from WebSocket
Oct 13, 2021 20:23:54.332 [0x7f5699bfbb38] Debug — Auth: authenticated user 1 as FLUDzilla
Oct 13, 2021 20:23:54.332 [0x7f56980bab38] Debug — Request: [192.168.1.217:42470 (Subnet)] GET /activities (16 live) GZIP Signed-in Token (FLUDzilla)
Oct 13, 2021 20:23:54.333 [0x7f5699c1eb38] Debug — Completed: [192.168.1.217:42470] 200 GET /activities (16 live) GZIP 1ms 350 bytes (pipelined: 8)
Oct 13, 2021 20:24:06.398 [0x7f5699c1eb38] Debug — Completed: [192.168.1.217:42478] 200 GET /player/proxy/poll?deviceClass=pc&protocolVersion=3&protocolCapabilities=timeline%2Cplayback%2Cnavigation%2Cmirror%2Cplayqueues&timeout=1 (15 live) GZIP 20001ms 5 bytes (pipelined: 11)
Oct 13, 2021 20:24:06.446 [0x7f5699c1eb38] Debug — Auth: authenticated user 1 as FLUDzilla
Oct 13, 2021 20:24:06.446 [0x7f56980bab38] Debug — Request: [192.168.1.217:42478 (Subnet)] GET /player/proxy/poll?deviceClass=pc&protocolVersion=3&protocolCapabilities=timeline%2Cplayback%2Cnavigation%2Cmirror%2Cplayqueues&timeout=1 (15 live) GZIP Signed-in Token (FLUDzilla)
Oct 13, 2021 20:24:06.446 [0x7f56980bab38] Debug — Content-Length is -1 (of total: -1).
Oct 13, 2021 20:24:07.746 [0x7f5699bfbb38] Debug — Completed: [192.168.1.229:59624] 200 GET /player/proxy/poll?deviceClass=pc&protocolVersion=3&protocolCapabilities=timeline%2Cplayback%2Cnavigation%2Cmirror%2Cplayqueues&timeout=1 (13 live) GZIP 20000ms 5 bytes (pipelined: 415)
Oct 13, 2021 20:24:07.751 [0x7f5699bfbb38] Debug — Auth: authenticated user 1 as FLUDzilla
Oct 13, 2021 20:24:07.751 [0x7f56980bab38] Debug — Request: [192.168.1.229:59624 (Subnet)] GET /player/proxy/poll?deviceClass=pc&protocolVersion=3&protocolCapabilities=timeline%2Cplayback%2Cnavigation%2Cmirror%2Cplayqueues&timeout=1 (13 live) GZIP Signed-in Token (FLUDzilla)
Oct 13, 2021 20:24:07.751 [0x7f56980bab38] Debug — Content-Length is -1 (of total: -1).
Oct 13, 2021 20:24:09.178 [0x7f5699bfbb38] Debug — CERT: incomplete TLS handshake from [::ffff:192.168.1.217]:42490: sslv3 alert certificate unknown
Oct 13, 2021 20:24:09.178 [0x7f5699c1eb38] Debug — CERT: incomplete TLS handshake from [::ffff:192.168.1.1]:50804: sslv3 alert certificate unknown
Oct 13, 2021 20:24:09.852 [0x7f5699bfbb38] Debug — EventSource: Got event [data] ‘’
Oct 13, 2021 20:24:09.853 [0x7f5699bfbb38] Debug — HTTP requesting GET https://downloads.plex.tv/relay/relay_v1.pub
Oct 13, 2021 20:24:09.964 [0x7f5699bfbb38] Debug — HTTP/2.0 (0.1s) 200 response from GET https://downloads.plex.tv/relay/relay_v1.pub
Oct 13, 2021 20:24:09.964 [0x7f5699bfbb38] Debug — Relay: refreshed host key from https://downloads.plex.tv/relay/relay_v1.pub
Oct 13, 2021 20:24:09.964 [0x7f5699bfbb38] Debug — Relay: starting relay.
Oct 13, 2021 20:24:09.964 [0x7f5699bfbb38] Debug — [JobRunner] Job running: PLEXTOKEN=‘xxxxxxxxxxxxxxxxxxxx’ ‘/snap/plexmediaserver/217/Plex Relay’ ‘-p’ ‘443’ ‘-N’ ‘-R’ ‘0:127.0.0.1:32401’ ‘-o’ ‘StrictHostKeyChecking=yes’ ‘-o’ ‘UserKnownHostsFile=/var/snap/plexmediaserver/common/Library/Application Support/Plex Media Server/Cache/relayHostKey.txt’ ‘-o’ ‘LogLevel=VERBOSE’ ‘-o’ ‘PreferredAuthentications=password’ ‘-o’ ‘PubkeyAuthentication=no’ ‘-l’ ‘FLUDzilla’ ‘-F’ ‘/dev/null’ ‘50.116.59.145’
Oct 13, 2021 20:24:09.965 [0x7f5699bfbb38] Debug — [JobRunner] Jobs: Starting child process with pid 72981
Oct 13, 2021 20:24:10.570 [0x7f56980bab38] Debug — [PlexRelay] Authenticated to 50.116.59.145 ([50.116.59.145]:443).
Oct 13, 2021 20:24:11.834 [0x7f56980bab38] Info — [PlexRelay] Allocated port 12909 for remote forward to 127.0.0.1:32401
Oct 13, 2021 20:24:12.278 [0x7f5699c1eb38] Debug — CERT: incomplete TLS handshake from 127.0.0.1:53840: sslv3 alert certificate unknown
Oct 13, 2021 20:24:15.651 [0x7f5699c1eb38] Debug — CERT: incomplete TLS handshake from [::ffff:192.168.1.217]:42492: sslv3 alert certificate unknown
Oct 13, 2021 20:24:15.657 [0x7f5699bfbb38] Debug — CERT: incomplete TLS handshake from [::ffff:192.168.1.1]:50806: sslv3 alert certificate unknown
Oct 13, 2021 20:24:15.791 [0x7f5699c1eb38] Debug — CERT: incomplete TLS handshake from 127.0.0.1:53842: sslv3 alert certificate unknown
Oct 13, 2021 20:24:20.706 [0x7f5699bfbb38] Debug — CERT: incomplete TLS handshake from [::ffff:192.168.1.217]:42494: sslv3 alert certificate unknown
Oct 13, 2021 20:24:20.712 [0x7f5699bfbb38] Debug — CERT: incomplete TLS handshake from [::ffff:192.168.1.1]:50808: sslv3 alert certificate unknown
Oct 13, 2021 20:24:20.831 [0x7f5699bfbb38] Debug — CERT: incomplete TLS handshake from 127.0.0.1:53844: sslv3 alert certificate unknown
Oct 13, 2021 20:24:26.448 [0x7f5699bfbb38] Debug — Completed: [192.168.1.217:42478] 200 GET /player/proxy/poll?
yes. Got it.
What are devices at 192.168.1.1 and 192.168.1.217 ?
Do you have a FQDN attached somewhere ?