9 days ago
Project: DriverStandard (d0dde47b-b0f3-4c14-88eb-ec37ac37873d)
Environment: production (2a60cb78-4143-41eb-949b-196f77977d28)
Service: driverstandard (fb48632b-bd56-43b5-827d-ff7ce2a2acd2)
Custom domain: app.driverstandard.app (06e0168e-09c2-4635-bba7-7a18a7abd84b)
Required CNAME target: 3s1j8gh7.up.railway.app
certificateStatus has been CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP since
approximately 10:26 BST on 26/09/2026. The edge serves the *.up.railway.app
wildcard certificate, so browsers show a certificate-name mismatch on the
production hostname.
Verified on our side
-
Your API reports the CNAME as DNS_RECORD_STATUS_PROPAGATED, and
requiredValue == currentValue == 3s1j8gh7.up.railway.app.
-
DNS is on Cloudflare, record is DNS-only (grey cloud), NOT proxied.
-
dig +short CNAME app.driverstandard.app @1.1.1.1 -> 3s1j8gh7.up.railway.app.
Authoritative check against dawn.ns.cloudflare.com returns the same.
-
No CAA records exist on driverstandard.app or app.driverstandard.app, so
Let's Encrypt is not blocked.
-
DNSSEC is NOT enabled (no DS, no DNSKEY), so it is not a DNSSEC failure.
-
The ACME challenge path is reachable and not redirected:
http://app.driverstandard.app/.well-known/acme-challenge/<random> -> 404 http://app.driverstandard.app/api/health -> 301 (expected)Response carries an x-railway header, confirming your edge is answering.
-
openssl s_client with -servername app.driverstandard.app returns
subject CN=*.up.railway.app, i.e. routing reaches Railway but the
domain-specific certificate has not been issued.
-
We called customDomainIssueCertificate for this domain id. It returned
true, but the status did not change.
-
The API exposes only ONE dnsRecord for this domain, purpose
DNS_RECORD_PURPOSE_TRAFFIC_ROUTE. No _railway-verify TXT record is
advertised. Several forum threads were resolved by adding such a TXT
record — if one is required here, please tell us the exact host and value
and we will add it immediately.
-
No incident listed on status.railway.com.
Note on retries
The domain was removed and re-added ONCE earlier, which regenerated the CNAME
target (7civ3q22 -> 3s1j8gh7). Cloudflare was updated to match and the API now
confirms the match. We have NOT repeated this, to stay well inside the
Let's Encrypt duplicate-certificate rate limit.
Request
Please investigate what is blocking issuance server-side and clear it, or tell
us the exact additional DNS record required. Happy to provide anything else.
0 Replies
Status changed to Awaiting Railway Response Railway • 9 days ago