I have recently setup Caddy with Let's Encrypt and custom domain for my SSL needs for homelab, however facing weird delay before every page refresh when visiting via iPhone. This is my setup:
- Let's Encrypt certs via DNS-01 (netcup)
- OPNsense + Unbound for internal DNS (split-horizon, resolves fine – 4ms)
- Hosting a internal web app (e.g. Otterwiki) on Proxmox LXC
Problem: On my MDM-managed iPhone, reloading the page (even same page) most of the time results in 2 second delay before the page loads. The delay is always consistently 2 seconds. When accessing via MacBook it's lightning fast.
What I tested:
- Direct IP to web app – no issues
- Through Caddy over plain HTTP – no issues
- SSL via Caddy's internal ACME CA (step-ca) – no issues, so it's really the Let's Encrypt DNS-01 path which is slow.
- Disabled HTTP/3, iCloud Private Relay, IP tracking – same issue
- Tried different browsers on iPhone – same issue
- If I block all internet access from iPhone – same issue
The cert has a CRL distribution point (ye1.c.lencr.org), so could it be that my iPhone is doing a synchronous CRL fetch that times out/downloads on every new page hit (which is enforced by MDM)? However, I don't see any requests going to Let's Encrypt via Internet, so I am not sure.
Any ideas what it could be and how I could further troubleshoot this?
Source: r/homelab · by /u/estrangedpulse