api.semseproject.com certificate stuck in VALIDATING_OWNERSHIP
samuelcastella
HOBBYOP

22 days ago

Production custom-domain TLS incident requiring Railway backend intervention.

Solved

3 Replies

Status changed to Awaiting Railway Response Railway 22 days ago


22 days ago

Your DNS records for api.semseproject.com are correctly configured, but the certificate verification pipeline got stuck before your DNS propagated and never re-ran. We've triggered a certificate re-issuance, which should complete verification and issue the TLS certificate within a few minutes.


Status changed to Awaiting User Response Railway 22 days ago


Status changed to Solved mykal 22 days ago


samuelcastella
HOBBYOP

22 days ago

Full technical evidence: Project SEMSEproject, project ID 95ad1b14-d1d9-467d-82d8-5354619ba873. Environment production, ID d682210a-956a-4508-9c5b-4ca5959278f9. Service semse-API, ID 2bd1bd3f-9aa1-4fc3-a714-4cf90c52c770. Domain api.semseproject.com, domain ID 5bf255b7-3ec8-45e8-86e3-f2a2dd89f647, created 2026-07-24, target port 3000. Current Railway state: sync ACTIVE, DNS CNAME PROPAGATED, exact Railway ownership TXT publicly propagated, verified no, certificate CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP for more than 7 days. DNS was independently confirmed through Cloudflare, Google, Quad9, and both authoritative nameservers. There are no CAA records blocking issuance and no DS or DNSSEC delegation issue. Application evidence: https://project-manager-app-production-977f.up.railway.app/v1/ready returns HTTP 200. Current API deployment 628a3941-21fa-408f-82ec-4b901d2c5eac is SUCCESS. Strict HTTPS to https://api.semseproject.com/v1/ready fails hostname verification with SEC_E_WRONG_PRINCIPAL and curl exit 60. Ignoring certificate verification only for diagnosis reaches the Railway edge but returns HTTP 404. Remediation attempted: target port explicitly aligned to 3000 with no status change. Certificate retry is unavailable because the domain never leaves VALIDATING_OWNERSHIP. Railway Agent confirmed a stalled platform certificate state requiring backend intervention in agent thread 6f73b5ae-9f3b-4ca5-b210-90a655b4689b. Requested action: please reset and re-run ownership verification and certificate or ACME provisioning for this existing domain. Preserve the domain and current DNS records if possible, and do not rotate the verification record unless strictly required. Please confirm after the reset so we can re-test /v1/ready over strict HTTPS.


Status changed to Awaiting Railway Response Railway 22 days ago


Status changed to Awaiting User Response mykal 22 days ago


22 days ago

The certificate re-issuance we triggered earlier has completed successfully. Your domain api.semseproject.com is now verified, the TLS certificate is valid, and edge routing is active - requests are being served with HTTP 200. You should be able to reach https://api.semseproject.com/v1/ready over strict HTTPS now.


Status changed to Solved mykal 22 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...