Apex custom domain TLS certificate fails with internal error
tetss2
HOBBYOP

23 days ago

Hello Railway team,

Please help us resolve an internal TLS certificate issuance failure for the apex custom domain kns.com.ua.

Project: kns-site-staging

Environment: production

Project ID: bd0233b9-f125-4123-a522-95e72b529cbc

Service: web

Service ID: 4ecf9710-e45e-4e2a-9946-b4a5ba521197

Active deployment ID: cea50c3e-c12c-4d9c-a843-fc936463a330

Railway service URL: https://web-production-554c2d.up.railway.app/

Custom domains: kns.com.ua and www.kns.com.ua (port 8080)

What happened on July 29, 2026:

  • The apex ALIAS and www CNAME were set to the exact targets shown by Railway.
  • Both Railway TXT ownership records propagated to all three authoritative nameservers.
  • There are no CAA records, and DNSSEC is not enabled.
  • Railway confirmed domain ownership.
  • www.kns.com.ua successfully received a Let's Encrypt certificate.
  • kns.com.ua remained at “Certificate Authority is validating challenges”, then changed to “Failed to issue TLS certificate — An internal error occurred”.
  • We clicked the built-in “Try Again” once. It immediately returned the same internal error instead of starting validation.
  • While failing, the apex served a *.up.railway.app certificate, producing a hostname mismatch and a 502 response in browsers.
  • The application itself remains Online and works correctly at the Railway service URL.

Because kns.com.ua is a production domain, we temporarily rolled only the apex/www web records back to the old host to restore visitor access. We kept both Railway custom domains configured and kept the Railway TXT verification records in DNS. Mail/MX and unrelated TXT records were never changed.

Could you please inspect the internal certificate issuance logs, clear or reset the stuck TLS state for kns.com.ua, and tell us when it is safe to point the apex and www records back to Railway? We do not want to delete/re-add the domain or repeatedly retry and risk a certificate authority rate limit.

Thank you.

Solved

1 Replies

Railway
BOT

23 days ago

The TLS certificate for kns.com.ua is now valid and fully issued on our side, so the internal error has cleared. The same is true for www.kns.com.ua. Both domains are verified and their certificates are ready to serve traffic.

To go live, point your DNS back to Railway: set the apex kns.com.ua CNAME (or ALIAS/ANAME, since it is an apex) to xl5hght1.up.railway.app and set www.kns.com.ua CNAME to mq9pjz9k.up.railway.app. Keep your existing _railway-verify TXT record in place. Once DNS propagates, both domains will serve over HTTPS with valid certificates. You can safely re-point them now, and reply here once updated so we can confirm everything looks good.


Status changed to Awaiting User Response Railway 23 days ago


Railway
BOT

16 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway 16 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...