SSL Certificate Reset - Difficult Cases

@ChuckPa
Can I get a little help too. My server isn’t reachable locally or remotely. I have the unable to connect to my server securely message. It also will randomly connect for about a minute before becoming unreachable again.

I’m also seeing the “CERT: incomplete TLS handshake: sslv3 alert certificate expired” errors on my server, have tried disabling/enabling remote access, restarting the server, updating the root CAs on the server, and the issue still persists, can you folks reset my certs from your end please? thanks

@ChuckPa
It’s Media and Jerflix servers.

1 Like

@runjerryrun Done. Done. Restart :slight_smile:

@ChuckPa
That did’t seem to work, perhaps I’m missing something? I restarted both servers as requested was there something else I needed to do?

@runjerryrun

I am going to need the DEBUG logs ZIP file, captured after a server restart and attempt to playback which fails.

@Mariah22pl

I reset your certificate earlier. It now sits with a valid 2-Oct creation date.
If that person cannot play from you, have you considered setting SecureConnections to “Preferred” ?

Also, I must ask if you have your own certificate attached to your Plex server .

@weega91

I have reset your certificate. Please restart the server.

@FugiTive-Legacy

Your certificate is new and valid as of today (2-Oct).
To be certain, I reset it again. Please restart the server.

After restarting the server, recheck the devices – restart as necessary

The Nvidia Shield can run HTTPS (required mode) as can all the iOS devies. I cannot speak to those Android devices but from what I do know – clearing their caches then restarting the device helps in a lot of networking problems (from a game I play).

Regarding the Synology at 1.21.0.3744, I do urge you to upgrade to current. There were a lot of changes since then as well as 1.21.0.3744 was BETA and is known to not be fully compatible with DSM 7.0.41890 (final release). If you have further questions, please create a new thread tagged “Server-Synology”.

1 Like

Plex Media Server Logs_2021-10-02_13-54-18.zip (384.5 KB)
@ChuckPa
Let me know if you need anything else. I appreciate all the help.

Thank a lot, I have been mashing that button the last 2 days. I’ll follow your suggestion, thanks again

FYI: “JerFlix” still sits there without certificate. Has it been restarted?

So I rebooted my server and I am still getting tons of “CERT: incomplete TLS handshake: sslv3 alert certificate expired” errors, I can playback without issue (insecure on LAN) but my friend cannot playback in chrome, error given in browser is “app.plex.tv is unable to connect to server securely”

my setting on the server is preferred for secure connections

heres an example

@ChuckPa
I have restarted the Plex service on my machine and also restarted the server a few times. Is there something I’m missing?

@flecom @runjerryrun

I have moved us to here.

This way, we can take the space to figure out why normal recovery procedure is not working.

@runjerryrun

Your host was seen 2 minutes ago as of this post and is still without certificate. Did you reset the correct Server.

@flecom
May I see the full log file set please ? I need put those errors in context. They’re rather useless that way because they don’t look like server errors.

Maybe I’m misunderstanding, is reset different from rebooting? I’ve rebooted the server that hosts Jerflix.

I can send you the logs but I seem to have fixed it, set the server to insecure only, restarted pms deleted the certificate in the plexmediaserver/cache directory, set it to secure connections preffered, Plex downloaded a new certificate and it seems to be working now as I see a bunch of streams now

Old cert had a datestamp of 10/2 so PMS did do something after you reset it on your end, not sure what went wrong, I have the old cert if it helps you troubleshoot also

I’m going to keep an eye on it but I fingers crossed we seem to be ok as I see both insecure and secure streams as expected

@flecom

Are you using a Rasplex? If so, they updated its certificate and now that works correctly.

no need to post morten the old cert.

With a new rasplex client, everything will work normally as preferred / required.

I have openpht on a Linux mint box but it’s via LAN so it works fine even before since it just connects insecure

Users were on all sorts of stuff, friend of mine that was helping me troubleshoot was just using Plex.TV on chrome and it kept telling him it was unable to establish a secure connection with my server until I blew away the cert and forced it to get another one

OK. That makes sense now.

You can add the IP of that device in Network settings and help it out.

There will come a time when OpenPHT fails completely so be perpared.

Yep have a transition plan away from Plex when they break it, just rather it be later vs sooner

Hi @ChuckPa
I disabled secure connections then did another reboot followed by setting secure connections back to preferred. After this I was able to get the green lock next to “Jerflix”. But only get the green lock through the local host, if I try to access through Plex.tv I get the insecure connection message. I was also able to play content on Apple TV locally.
I next turned off remote access for about 12 hours. After enabling it again was able to play content on my iPhone with while not on my network but when I checked Varys it showed the stream as an insecure connection. I set secure connection to required and tried to play a movie on my phone outside my network again. This time the movie would not play. I also had another uses play a movie and they were successful but still the stream has an unsecure connection.
So at this point I believe I am able to play content locally and remotely but not with a secure connection. Also I am not able to access “Jerflix” through the Plex web app at all. It shows as unreachable with the message about connecting securely.

@ChuckPa
Is there a better channel I should go through for help? Any advice or help would be greatly appreciated.