If you are using the following relays, beware that many clients will not connect, upload or download data from them. Amethyst Push Notifications will also not connect to them.

- wss://relay.orangepill.dev certificate has expired

- wss://ca.relayable.org certificate has expired

- wss://nostr.btcmp.com certificate has expired

- wss://nostr.delo.software certificate has expired

- wss://nostr.drss.io Hostname/IP does not match certificate's altnames: Host: nostr.drss.io. is not in the cert's altnames: DNS:nostr.io, DNS:www.nostr.io

- wss://nostr.libreleaf.com certificate has expired

- wss://nostr.mikedilger.com Hostname/IP does not match certificate's altnames: Host: nostr.mikedilger.com. is not in the cert's altnames: DNS:chorus.mikedilger.com

- wss://nostr.onsats.org Hostname/IP does not match certificate's altnames: Host: nostr.onsats.org. is not in the cert's altnames: DNS:onsats.org

- wss://nostr.openordex.org certificate has expired

- wss://nostr.orangepill.dev certificate has expired

- wss://nostr.plebchain.org certificate has expired

- wss://nostr.unknown.place self-signed certificate

- wss://nostr.walletofsatoshi.com certificate has expired

- wss://nostr.zaprite.io Hostname/IP does not match certificate's altnames: Host: nostr.zaprite.io. is not in the cert's altnames: DNS:examplewalk.com, DNS:www.examplewalk.com

- wss://nostr.zebedee.cloud Hostname/IP does not match certificate's altnames: Host: nostr.zebedee.cloud. is not in the cert's altnames: DNS:names-hub.com, DNS:www.names-hub.com

- wss://private.red.gn.net certificate has expired

- wss://relay.nostr.ro certificate has expired

- wss://relay.orangepill.dev certificate has expired

- wss://relayable.org certificate has expired

Reply to this note

Please Login to reply.

Discussion

Ty for letting us know

An automated service that polls known relays periodically and logs some stats (age of the last N notes to estimate usage), logs unusable relays, and has a simple web frontend would be nice. Any additional diagnostics are a bonus but I'm sure people could come up with a bevy of them.

With NIP-66, yes. These expired certificates can be found in `30066` events right now. And yes, next nostr.watch would convey these details, and any other data present. But then again, any client could convey those conclusions at runtime with NIP-66

Sent you a private message on 25 June. Am curious to know where I can securely disclose a security issue impacting nostr.watch.

Just message me or post an issue on Github.

I wish we would have a relay dashboard score

So relayable is really reliable.

What is the reason for this? Is there something technical, operational or intentional or something else entirely?

I think a lot of them are probably not maintained anymore

Feel free to use

wss://nostr.kolbers.de

I just assumed that some of these were no longer maintained, but maybe they'll work without SSL?

No they won't work. The wss bit means it must be a secured socket connection the same way that https requires a secured connection or it will fail.

It has to fail. If the socket can't be encrypted because the encryption certificate isn't correct, you can't just default to having no encryption and continue working because that's more convenient.

what if we specify the same domains with wsโ‹ฎ// ?

Nope, because wss and ws listen on different ports the same way that http and https listen on different ports 80 and 443 respectively.

Someone would need to have intentionally setup a relay that wasn't encrypted so that anyone using the relay would have their IP address and other details available for the entire world to track.

The only way you can use a non secured socket 'ws' is with a TOR encrypted tunnel which means the socket is still encrypted anyway.

Admins should use automated letsencrypt if they don't want to pay for a cert..

How does one get more relays and whatโ€™s is the point of having more relays? (I only have three, none on that list)

Relays are home for your data. 3 are enough. Just make sure you trust the operators behind the 3 relays you are using

smooth operators

uh, wss is

Clownshow superbowl (the debate) is predictable, lame and a waste of everyone's time.

Auditing/managing/fixing your relays for optimal nostr experience is not.

nostr:nevent1qqsqf6nnphlgnarrj9qtrrfupfjvwj3lgh8h5frpdtkfdddj53u3y3qpzpmhxue69uhkummnw3ezuamfdejsygzxpsj7dqha57pjk5k37gkn6g4nzakewtmqmnwryyhd3jfwlpgxtspsgqqqqqqsgnxjlt

We need an easier way to run relays. I want to run my own relay but I am not able to install a relay on shared hosting.

I only need a relay for myself. I don't want others using my relay.

If they made it easier. There would be many people running their own relays for themselves.

This all reminds me when Forums, WordPress, mastodon was new.

Everyone runs out and installs the software to try it and and then they forget about it.

Certificate expired is more a warning than an error, imho. Can in many cases be ignored by smart software.

Itโ€™s good to know, purging the relays is also important for a better experience #nostr

I usually go to the universe and disconnect everyone, then I try one by one and see if they are broadcasting to date.

Itโ€™s rudimentary but it works.

nostr.drss.io is completely down, but they say that it will return.

There's definitely something wrong with Zebedee's Nostr relay.