Certificate Authority is validating challenges
voidkandy
HOBBYOP

2 months ago

Out of nowhere my site's certificates stopped working. Now I keep getting this warning that railway 'failed to issue TLS certificate'. When I try, it just gets stuck on 'Certificate Authority is validating challenges'

I found this other issue: https://station.railway.com/questions/certificate-authority-is-validating-chal-7670b244

It says 'solved' but I see nothing about how

Attachments

Solved

34 Replies

2 months ago

Can you check its configuration again?


Status changed to Awaiting User Response Railway about 2 months ago


noahd

Can you check its configuration again?

voidkandy
HOBBYOP

2 months ago

Yeah, looks like I needed to update my DNS records. I did that and now I'm seeing "Certificate Authority is validating challenges" again


Status changed to Awaiting Railway Response Railway about 2 months ago


According to the linked resource, I see a valid cert. Is that still the case?


Status changed to Awaiting User Response Railway about 2 months ago


robertramosastudillo
HOBBY

2 months ago

I'm facing the exact same issue with my wildcard domain *.ordenly.co.

Important Context: This setup was working perfectly 2 days ago and suddenly started failing. I haven't changed my DNS provider.

The symptoms:

  1. Stuck on "Certificate Authority is validating challenges" for 24+ hours.

  2. Eventually fails with "Failed to issue TLS certificate" (Internal Error).

  3. Retrying puts it back in the infinite validation loop.

My Configuration (Verified):

  • DNS Records: Validated CNAME for both wildcard (*) and _acme-challenge. Both point to the correct Railway target provided (uyofr105...).

  • Cloudflare Settings: _acme-challenge is strictly set to DNS Only (Grey Cloud). Universal SSL is Enabled.

  • Troubleshooting tried: I have already tried deleting the domain, waiting, and re-adding it to force a reset, but the issue persists.

It seems like the internal validation process is hanging indefinitely. Could you please check the logs for *.ordenly.co?


Status changed to Awaiting Railway Response Railway about 2 months ago


angelo-railway

According to the linked resource, I see a valid cert. Is that still the case?

voidkandy
HOBBYOP

2 months ago

No, I'm still having the same issue


robertramosastudillo

I'm facing the exact same issue with my wildcard domain *.ordenly.co.Important Context: This setup was working perfectly 2 days ago and suddenly started failing. I haven't changed my DNS provider.The symptoms:Stuck on "Certificate Authority is validating challenges" for 24+ hours.Eventually fails with "Failed to issue TLS certificate" (Internal Error).Retrying puts it back in the infinite validation loop.My Configuration (Verified):DNS Records: Validated CNAME for both wildcard (*) and _acme-challenge. Both point to the correct Railway target provided (uyofr105...).Cloudflare Settings: _acme-challenge is strictly set to DNS Only (Grey Cloud). Universal SSL is Enabled.Troubleshooting tried: I have already tried deleting the domain, waiting, and re-adding it to force a reset, but the issue persists.It seems like the internal validation process is hanging indefinitely. Could you please check the logs for *.ordenly.co?

voidkandy
HOBBYOP

2 months ago

Yeah this is pretty much exactly what I'm dealing with


Railway
BOT

a month ago

Hello!

We're acknowledging your issue and attaching a ticket to this thread.

We don't have an ETA for it, but, our engineering team will take a look and you will be updated as we update the ticket.

Please reply to this thread if you have any questions!


Railway
BOT

a month ago

🛠️ The ticket SSL Certificate Validation has been marked as triage.


Noted, I am going to be raising this up to the team to see what might have went wrong. I apologize for the impact.


Status changed to Awaiting User Response Railway about 2 months ago


voidkandy
HOBBYOP

a month ago

Any updates on this? I'm at about a week of my site being down now : (


Status changed to Awaiting Railway Response Railway about 1 month ago


rafranck17
HOBBY

a month ago

I have the same issue on a new site I am creating. Can I get added to receive updates on the ticket?


a month ago

Can y'all make your own threads for this? Would be able to track the issues individually better!


Status changed to Awaiting User Response Railway about 1 month ago


noahd

Can y'all make your own threads for this? Would be able to track the issues individually better!

voidkandy
HOBBYOP

a month ago

Since this is originally my thread would you like me to open a new one as well?


Status changed to Awaiting Railway Response Railway about 1 month ago


voidkandy

Since this is originally my thread would you like me to open a new one as well?

a month ago

Nope if you're the OP use this!


Status changed to Awaiting User Response Railway about 1 month ago


voidkandy
HOBBYOP

a month ago

Almost two weeks now of my website being down. Are there any updates?


Status changed to Awaiting Railway Response Railway about 1 month ago


Railway
BOT

a month ago

Hello!

We're acknowledging your issue and attaching a ticket to this thread.

We don't have an ETA for it, but, our engineering team will take a look and you will be updated as we update the ticket.

Please reply to this thread if you have any questions!


sam-a
EMPLOYEE

a month ago

Hey there, sorry for the trouble with your certificate!

Your DNS records for *.voidkandy.space are pointing to an outdated target. You'll need to update them to match the current values shown in your Railway dashboard.

Specifically, update your CNAME record to point to qzgyoke7.railway.internal (instead of the old mrbury9f value). Once that propagates, the certificate should validate automatically.

Let us know if you run into any issues after updating.


Status changed to Awaiting User Response Railway about 1 month ago


sam-a

Hey there, sorry for the trouble with your certificate!Your DNS records for *.voidkandy.space are pointing to an outdated target. You'll need to update them to match the current values shown in your Railway dashboard.Specifically, update your CNAME record to point to qzgyoke7.railway.internal (instead of the old mrbury9f value). Once that propagates, the certificate should validate automatically.Let us know if you run into any issues after updating.

voidkandy
HOBBYOP

a month ago

Okay, I've updated my records accordingly. I will let you know what happens :)


Status changed to Awaiting Railway Response Railway about 1 month ago


sam-a
EMPLOYEE

a month ago

Groundhog day was recently, and I imagine you might feel like you are living the movie. I see you are stuck again on "Certificate Authority is validating challenges". Could you try the troubleshooting steps at https://docs.railway.com/guides/troubleshooting-ssl#certificate-stuck-on-validating-challenges one more time? Particularly, if you have not tried removing and re-adding. Just try it once and if does not succeed we'll investigate further.

Thanks so much for your patience.


Status changed to Awaiting User Response Railway about 1 month ago


voidkandy
HOBBYOP

a month ago

It looks like there are some issues according to https://dnsviz.net/d/www.voidkandy.space/dnssec/

I have no idea how to address these

Attachments


Status changed to Awaiting Railway Response Railway about 1 month ago


sam-a

Groundhog day was recently, and I imagine you might feel like you are living the movie. I see you are stuck again on "Certificate Authority is validating challenges". Could you try the troubleshooting steps at https://docs.railway.com/guides/troubleshooting-ssl#certificate-stuck-on-validating-challenges one more time? Particularly, if you have not tried removing and re-adding. Just try it once and if does not succeed we'll investigate further.Thanks so much for your patience.

robertramosastudillo
HOBBY

a month ago

Hi team, I'm following up here because it's been 6 days since I opened my separate thread as requested, and my production site (*.ordenly.co) has now been down for nearly 3 weeks in total.

This is a multi-tenant SaaS and the 'Certificate Authority is validating challenges' loop is affecting all my customers. I’ve already performed all the troubleshooting steps (DNS-only in Cloudflare, deleting/re-adding the domain).

Could someone please manually check if there is a target mismatch on the backend? Here is my thread: https://station.railway.com/community/certificate-authority-is-validating-chal-c52c3835


sam-a

Groundhog day was recently, and I imagine you might feel like you are living the movie. I see you are stuck again on "Certificate Authority is validating challenges". Could you try the troubleshooting steps at https://docs.railway.com/guides/troubleshooting-ssl#certificate-stuck-on-validating-challenges one more time? Particularly, if you have not tried removing and re-adding. Just try it once and if does not succeed we'll investigate further.Thanks so much for your patience.

voidkandy
HOBBYOP

a month ago

It looks like changing my DNS records did not fix anything


voidkandy

It looks like changing my DNS records did not fix anything

voidkandy
HOBBYOP

a month ago

I don't know if this is the right thread to request this but I would like a partial refund for this month's subscriptions since my site has been down for the passed 2 weeks


voidkandy

I don't know if this is the right thread to request this but I would like a partial refund for this month's subscriptions since my site has been down for the passed 2 weeks

a month ago

It'd be best to make your own thread for that!


Status changed to Awaiting User Response Railway about 1 month ago


Railway
BOT

a month ago

🛠️ The ticket Secure connection setup issue has been marked as todo.


Railway
BOT

a month ago

🛠️ The ticket SSL Certificate Validation has been marked as todo.


diana
PRO

a month ago

Hello, we have fixed the underlying issue and the certificate has been issued successfully. Please let us know if you have any questions.


diana

Hello, we have fixed the underlying issue and the certificate has been issued successfully. Please let us know if you have any questions.

voidkandy
HOBBYOP

24 days ago

This issue has not been resolved for me. Nothing has changed.


Status changed to Awaiting Railway Response Railway 24 days ago


24 days ago

There are stale TXT records on your domain. You will need to ask your NS provider to clear those before we can issue a certificate for the wildcard subdomain.


Status changed to Awaiting User Response Railway 24 days ago


brody

There are stale TXT records on your domain. You will need to ask your NS provider to clear those before we can issue a certificate for the wildcard subdomain.

voidkandy
HOBBYOP

22 days ago

which records specifically?


Status changed to Awaiting Railway Response Railway 22 days ago


22 days ago

The TXT records for the ACME verification.


Status changed to Awaiting User Response Railway 22 days ago


brody

The TXT records for the ACME verification.

voidkandy
HOBBYOP

22 days ago

Thanks I've just cleared those


Status changed to Awaiting Railway Response Railway 22 days ago


voidkandy
HOBBYOP

22 days ago

This issue is fixed on my end thank you!


22 days ago

Awesome, glad you are in a good state now!


Status changed to Awaiting User Response Railway 22 days ago


Status changed to Solved brody 22 days ago


Loading...