24 days ago
Hi, I'm not sure if the issue was completely solved. I'm still having SSL errors:
```Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection.
Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
```
Project: 76befed3-8115-4ada-a38d-25458ed0565b
Service: bf080c6f-ead5-4ae4-ab60-740d16e09344
190 Replies
24 days ago
Ack, Looking into it right now!
24 days ago
I am getting the same error too. I use Cloudflare as well but this issue is new and we didn't change anything
24 days ago
Same here!
Project: 01485e2d-34be-40e1-9b0e-92134db9b54a
Service: 16ab0087-a6b1-4d12-8e70-287af744b86c
24 days ago
Provide domain please?
24 days ago
Yep, seems like a Fastly <> CF issue
24 days ago
Angelo - Can you look it up from this so I don't have to expose the domain?
Project: 01485e2d-34be-40e1-9b0e-92134db9b54a
Service: 16ab0087-a6b1-4d12-8e70-287af744b86c
24 days ago
Talking with both teams
yeah we have an old domain pointed to our otelcol instance (made way before the cf one click update) and that one works
24 days ago
Note for everyone on the thread, we put all domains behind a CDN to give DDoS protection by default, hence the issue.
24 days ago
Yea, ack, networking team working on it
24 days ago
You'd get an email
24 days ago
2nd P0 issue in a week. 
Please keep up posted on a resolution.
12unicorns
2nd P0 issue in a week.Please keep up posted on a resolution.
24 days ago
Domain? We are working on excepting people affected to move 'em off of Fastly.
angelo-railway
Domain? We are working on excepting people affected to move 'em off of Fastly.
24 days ago
stacks.africa, dashboard.stacks.africa, africaawesome.com
Thank you!
24 days ago
Seeing the same issue on multiple projects & services. Behind cloudflare as well.
24 days ago
For the record, we set up the CDN as a broad shield against DDoS attacks to make it so that we would make it so that other workloads wouldn't bring down yours, seems like there is some cert disagreement between Cloudflare and Fastly.
24 days ago
this seems very widespread, it's impacting me as well on multiple sites
jerrett
this seems very widespread, it's impacting me as well on multiple sites
24 days ago
Domain? Raising to the network team.
24 days ago
Hey angelo, would you able to look at quack.food as well please? its been over an hour and users are panicking.
24 days ago
What is the cause of this? Did you do a big infrastructure change yesterday?
The Fastly SAN certs seems to miss domains etc. idd.
Plan is to move us off and then on again later?
Eta?
24 days ago
I have my entire website down. I use cloudflare for DNS with proxy mode on. Is there a solution for this issue yet?
24 days ago
Network workaround from the eng. team is mentioning that re-adding the domain should restore access. Can you folks attempt that?
24 days ago
Same thing, re-added the domain and cloudflare dns
24 days ago
One other question network eng. has is if these are root domains in CF?
24 days ago
Yes
24 days ago
Root and sub in CF and Railway
I tried readding already awhile ago. Also remove the proxy and allow dns to flow. Same error. And yes same as above
angelo-railway
Network workaround from the eng. team is mentioning that re-adding the domain should restore access. Can you folks attempt that?
24 days ago
This does not work. I tried adding an additional domain - same issue.
24 days ago
Noted, Network Eng. has fresh logs that they are looking at. Is it possible for you to disable CF if it's in the critical path?
24 days ago
Readding domain does not work, tried adding one more domain. How much time it can take? We are losing money :(
24 days ago
I gave the wrong project and service before, that project and service was running.
it's this not running:
Project: 3816cd49-1c8a-4c26-a2aa-7656f8c9b6da
Service: a9869caa-d423-41cb-9ed1-96efea0cd26f
I just tried readding the domain, does not work yet.
24 days ago
Heard, still working through it, if you can disable CF that would be the workaround. The irony is not lost on us after years of recommending CF name servers.
24 days ago
Hello, we’ve encountered this issue and our services are currently down. How can we fix it? Our customers are waiting and we can’t provide service — we’re losing money and reputation. What’s the solution?
bonfi.az
24 days ago
Re added the domain and turned off proxying on cloudflare, still seeing the same error
24 days ago
Can’t you roll back whatever you did yesterday?24 days ago
Okay, we got recovery in one with a mitigation, we're going to work down the list.
angelo-railway
Domain? Raising to the network team.
24 days ago
24 days ago
It has nothing to do with Claudflare, and everything to do with your Fastly SAN certs.
We can't disable Claudflare lol, we use zero auth for traffic filtering.
Maybe update your status: https://status.railway.com/
angelo-railway
Okay, we got recovery in one with a mitigation, we're going to work down the list.
24 days ago
Awesome! Do you need any info about the project and service?
Issue persists at bloxgame.com and bloxgame.us
24 days ago
deleted
24 days ago
Still need help here guys
76befed3-8115-4ada-a38d-25458ed0565b
bf080c6f-ead5-4ae4-ab60-740d16e09344
24 days ago
p
angelo-railway
Try now
24 days ago
https://singwiththestars.com/ still an issue on my site as well thanks so much for your help.
jerrett
lamplit.cacelebratorygathering.ca
24 days ago
Got not found for this one :|
24 days ago
can you check this please, its been over an hour
https://quack.food/
Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection. Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
scaletoinfinity
I gave the wrong project and service before, that project and service was running. it's this not running:Project: 3816cd49-1c8a-4c26-a2aa-7656f8c9b6daService: a9869caa-d423-41cb-9ed1-96efea0cd26fI just tried readding the domain, does not work yet.
24 days ago
We seem to be back on that service, can you confirm?
hwhelchel
https://singwiththestars.com/ still an issue on my site as well thanks so much for your help.
24 days ago
Back
24 days ago
We’re having the same issue as well on https://bonfi.az. What can we do to help you support us?
keef
can you check this please, its been over an hourhttps://quack.food/Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection. Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
24 days ago
Triggered mitigation, will take a min to propagate.
angelo-railway
Back
24 days ago
thank you so much
24 days ago
p
24 days ago
Hi, catching up on this, tried removing/creating a custom domain, is the 404 issue for newly created domains separate from the CF issue? Also hosted on CF
markkdev
Hi, catching up on this, tried removing/creating a custom domain, is the 404 issue for newly created domains separate from the CF issue? Also hosted on CF
24 days ago
Domain please?
24 days ago
Status on this?
Project: 3816cd49-1c8a-4c26-a2aa-7656f8c9b6da
Service: a9869caa-d423-41cb-9ed1-96efea0cd26f
24 days ago
I tried removing and adding domain on railway and I am now getting SSL handshake failed Error code 525. Please help me how to resolve this issue
24 days ago
I having same issue as well
project id: a5759242-e792-4557-ac67-c246887aba6a
angelo-railway
Triggered mitigation, will take a min to propagate.
24 days ago
thank you for the quick response, much appreciated
24 days ago
Still down: api.bldr.chat and bldr.chat
12unicorns
stacks.africa, dashboard.stacks.africa, africaawesome.comThank you!
24 days ago
@Angelo, could you please assist.
angelo-railway
Domain please?
24 days ago
reelstorage.com
24 days ago
ya'll shold really roll it back and figure out a fix that doesn't involve manually dealing with every cloudflare domain, just sayin' 
24 days ago
p
angelo-railway
https://www.bonfi.az/ is back
24 days ago
What does that mean? Should it be working now? I’m checking, but it’s still not working.
azbonfi
We’re having the same issue as well on https://bonfi.az. What can we do to help you support us?
24 days ago
Might need to hard refresh, loading on my side.
24 days ago
p
24 days ago
Has the issue been fixed for anyone? If you react to this message, we can tell who it’s working for and who is still experiencing the problem.
azbonfi
Has the issue been fixed for anyone? If you react to this message, we can tell who it’s working for and who is still experiencing the problem.
24 days ago
This is your site loading fine from USE.
Attachments
24 days ago
Same Issue
project: e8e680d7-7b9c-4ced-8933-c7db32634ef2
service: e64f9d88-c3f6-4ad8-b7bf-32d7cd8bdebd
baoa111
I having same issue as well project id: a5759242-e792-4557-ac67-c246887aba6a
24 days ago
Mitigations applied
chrisswhitneyy
api.piquetickets.com project id: 5e043e61-0757-4a02-bb7e-07d2b24b7ea2
24 days ago
back up, gracias
24 days ago
Thanks for your help @angelo-railway, best of luck to the folks on call getting through this tonight.
plinpod
Same Issueproject: e8e680d7-7b9c-4ced-8933-c7db32634ef2service: e64f9d88-c3f6-4ad8-b7bf-32d7cd8bdebd
24 days ago
Mitigations applied
24 days ago
Can you please help me with Teamfundraising.org please. It's been over an hour and I am already getting emails from my customers
junkzen
Can we get our app fixed? https://mockwell.ai/
24 days ago
Mitigations applied
angelo-railway
Mitigations applied
24 days ago
thank you!
bathai
Can you please help me with Teamfundraising.org please. It's been over an hour and I am already getting emails from my customers
24 days ago
webhooks.teamfundraising.org mitigations applied to this one
angelo-railway
Mitigations applied
24 days ago
Can you take a look at https://api.bldr.chat please? I opened the conversation 🥹
junkzen
Can we get our app fixed? https://mockwell.ai/
24 days ago
Mitigatons applied
24 days ago
Every day it's something else...
24 days ago
What about other subdomains? I changed the *.teamfundraising.org to new domain like you asked on Railway and now I am getting SSL handshake failed Error code 525
24 days ago
Having the same issues on https://api.kyubi.gg/, https://prod.kyubi.gg/ thanks!
devhowyalike
Every day it's something else...
24 days ago
If you aren't providing a domain, please refrain so others can get assistance. We gave everyone a CDN however, we can't test for every single combination of cert out there, apologies.
angelo-railway
This is your site loading fine from USE.
24 days ago
I’m currently in Azerbaijan and I’ve tested from here on several devices, but it’s still not working. Could the issue vary by country?
Attachments
24 days ago
Same issue fac07f91-55dd-4092-8e85-4a0dc22042b3, fix please. Domain: https://pumpit.tech/
kenny019
Having the same issues on https://api.kyubi.gg/, https://prod.kyubi.gg/ thanks!
24 days ago
Mitigations applied
zemetsskiy
Same issue fac07f91-55dd-4092-8e85-4a0dc22042b3, fix please. Domain: https://pumpit.tech/
24 days ago
Mitigations applied
24 days ago
https://legacyfoundationresourceguide.org/ project id: ae6fc20f-9a50-4c38-a7e0-18904187a394
24 days ago
rapgpt.app
azbonfi
I’m currently in Azerbaijan and I’ve tested from here on several devices, but it’s still not working. Could the issue vary by country?
24 days ago
Try incognito?
12unicorns
stacks.africa, dashboard.stacks.africa, africaawesome.com
24 days ago
It's loading on my end. Asking the network eng. to see if it's an issue with POP terminating traffic close to you.
12unicorns
stacks.africa, dashboard.stacks.africa, africaawesome.com
24 days ago
Here it is loading on my end btw, still asking the on-call for more info for you.
Attachments
24 days ago
Having the same issue, project: 7762f0f0-4e65-4dfa-b811-481995f410da, domain: https://pets-care.app/. Thank you in advance.
chrisswhitneyy
https://legacyfoundationresourceguide.org/ project id: ae6fc20f-9a50-4c38-a7e0-18904187a394
24 days ago
mitigations applied
24 days ago
Thanks.
seweryn-skillfuldevelopers
Having the same issue, project: 7762f0f0-4e65-4dfa-b811-481995f410da, domain: https://pets-care.app/. Thank you in advance.
24 days ago
mitigations applied
24 days ago
@angelo, I am getting SSL handshake failed Error code 525.
You ignored my main domain and resolved the webhooks subdomain. Can you please resolve *.teamfundraising.org?
Attachments
24 days ago
Again, massive apologies on our side, it's been never ending. However, I think this is it. Namely, we had to apply a CDN in front of every one because DDoS targets on our machines would blow up proxies adjacent to your workload. After enabling this, we have fully mitigated all DDoS traffic.
However, cert creation and propagation is a bit... non standard so we're backfilling certs now for ones not reported.
bathai
@angelo, I am getting SSL handshake failed Error code 525.You ignored my main domain and resolved the webhooks subdomain. Can you please resolve *.teamfundraising.org?
24 days ago
It's moved, so the error is not Fastly.
24 days ago
cms.ptgis.id project id: 8c77d9d3-4622-48cb-bf3d-b09363b550f8
Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection.
Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.razrinn
cms.ptgis.id project id: 8c77d9d3-4622-48cb-bf3d-b09363b550f8Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection. Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
24 days ago
Mitigations applied
24 days ago
mine are still borked, one is "Issuing TLS certificate"
24 days ago
Hi, same issue here: Invalid SSL certificate Error code 526
project: 34c8d31a-ad64-43f8-a20d-3f009f7bc34a
url: https://www.omchattyai.com/
angelo-railway
Mitigations applied
24 days ago
alright its up now, thx
24 days ago
But I started seeing this error after reassigning the domain in railway like you asked. Do you have any solutions for this issue?
bathai
But I started seeing this error after reassigning the domain in railway like you asked. Do you have any solutions for this issue?
24 days ago
You will have to re-add, it would appear that the record you readded is malformed. (Given the error that I am seeing.)
24 days ago
not working.
Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection.
Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
help pls
bonfi.az
24 days ago
project id: 968fbf0e-c851-4e88-a772-1ece2d77f4be
service id: 874ab1b1-f4d1-460a-8cc8-ea426df9ee70
24 days ago
Hi @angelo, It's now back to the original error after I readded the domain again
Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection. Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
This is for *.teamfundraising.org
azbonfi
not working.Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection. Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.help plsbonfi.az
24 days ago
Dig is showing that your domain isn't CNAMEed, can you check that?
24 days ago
Hi all, Same issues on all my apps
Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection.
Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
i'm worry i saw that issue i solved but not for me
angelo-railway
Dig is showing that your domain isn't CNAMEed, can you check that?
24 days ago
https://www.bonfi.az this working but https://bonfi.az this not working
meranhor
Hi all, Same issues on all my appsRequested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection. Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.i'm worry i saw that issue i solved but not for me
24 days ago
domain please?
azbonfi
https://www.bonfi.az this working but https://bonfi.az this not working
24 days ago
You are witnessing the slow slow slow march of DNS, I am sure in AZ it will take a bit.
ekg.ggproject id: 968fbf0e-c851-4e88-a772-1ece2d77f4beservice id: 874ab1b1-f4d1-460a-8cc8-ea426df9ee70
24 days ago
Mitigations applied
24 days ago
Can you please apply whatever mitigations you are doing to *.teamfundraising.org? I am losing money and sleep over this issue
angelo-railway
Here it is loading on my end btw, still asking the on-call for more info for you.
24 days ago
can you please check:
bolorindem.am
24 days ago
Domaine :
www.starshipdealers.com
Project ID : f31a4eb5-0f32-444c-bdde-44f1a1d9b88e
24 days ago
Can you please fix: bolorindem.am, I am having the same issue
Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection.
Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
24 days ago
Same error here: turixe.com
24 days ago
Other projects seem to be working fine. This is a host error. 526.
bathai
Can you please apply whatever mitigations you are doing to *.teamfundraising.org? I am losing money and sleep over this issue
24 days ago
Apparently you hardcoded the IP in the DNS record, this is why it's failing.
arkoc
Can you please fix: bolorindem.am, I am having the same issueRequested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection. Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
24 days ago
Mitigations applied
angelo-railway
mitigations applied
24 days ago
Still not working
24 days ago
That's incorrect. I am not talking about teamfundraising.org which points to a different host. I am talking about *.teamfundraising.org which is a wildcard subdomain which points to vettfkit.authorize.railwaydns.net currently in my CF DNS record
bathai
That's incorrect. I am not talking about teamfundraising.org which points to a different host. I am talking about *.teamfundraising.org which is a wildcard subdomain which points to vettfkit.authorize.railwaydns.net currently in my CF DNS record
24 days ago
Gotcha, fix applied to that too.
24 days ago
Not helpful because it now says SSL handshake failed Error code 525
Status changed to Awaiting Railway Response brody • 24 days ago
bathai
Not helpful because it now says SSL handshake failed Error code 525
24 days ago
Please make sure you have your TLS/SSL mode set to Full.
Status changed to Awaiting User Response Railway • 24 days ago
24 days ago
Yes, it is full
Status changed to Awaiting Railway Response Railway • 24 days ago
24 days ago
Do we need to give you the specific domains impacted for you to apply a fix? Seems a bit painful! Or... are you able to fix it for all without know all the impacted domains?
24 days ago
I'm also experiencing issues for my services for this project: 20bf859d-0d7f-4dac-b13c-40c2fde1c166
rjbathgate
Do we need to give you the specific domains impacted for you to apply a fix? Seems a bit painful! Or... are you able to fix it for all without know all the impacted domains?
24 days ago
We have a backfill script running as we speak, but we are expediting recovery for anyone who just hands us domains.
The other issue is that we are finding a lot of A records (unsupported) and hardcoded IPs, or improper TLS so we are also working through that.
(Exception Bathai, we are looking into it)
djordje-st
I'm also experiencing issues for my services for this project: 20bf859d-0d7f-4dac-b13c-40c2fde1c166https://usemapstore.com/http://app.usemapstore.com/
24 days ago
Mitigations applied
Status changed to Awaiting User Response Railway • 24 days ago
angelo-railway
We have a backfill script running as we speak, but we are expediting recovery for anyone who just hands us domains.The other issue is that we are finding a lot of A records (unsupported) and hardcoded IPs, or improper TLS so we are also working through that.(Exception Bathai, we are looking into it)
24 days ago
admin.wildthings.club (only that specific subdomain is impacted)
FYI if you try and access that domain it'll redirect you to www due to firewall rules but for me, it doesn't redirect and I land on the cert issue.
Status changed to Awaiting Railway Response Railway • 24 days ago
rjbathgate
admin.wildthings.club (only that specific subdomain is impacted)FYI if you try and access that domain it'll redirect you to www due to firewall rules but for me, it doesn't redirect and I land on the cert issue.
24 days ago
Applied.
Status changed to Awaiting User Response Railway • 24 days ago
24 days ago
same issue Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [766821fba06a18fd70cf5cd51bcdf1cea3997473edbf7d8d245190f7a09cbb76] in use with this connection. Visit https://www.fastly.com/documentation/guides/concepts/errors/#routing-errors for more information.
Status changed to Awaiting Railway Response Railway • 24 days ago
24 days ago
Same issue on online.haprofessor.com , hundreds of users cannot login in and we're in the middle of a presentation. Tried deleting and readding the domain, didn't help.
24 days ago
Brody and Angelo, any resolution found yet? I turned off the proxy in CF and now I am getting SSL handshake failed error page.
24 days ago
same issue on 0a9a0b99-8eec-40b5-ad3a-2892392373e0
24 days ago
Domaine : https://staging.starshipdealers.com/
f31a4eb5-0f32-444c-bdde-44f1a1d9b88e
This subdomain have the same issue but you already corrected the main domain , normal ?
brody
Applied.
24 days ago
Fixed, thanks
bathai
Brody and Angelo, any resolution found yet? I turned off the proxy in CF and now I am getting SSL handshake failed error page.
24 days ago
Both domains are working for us.
Status changed to Awaiting User Response Railway • 24 days ago
Status changed to Awaiting Railway Response Railway • 24 days ago
24 days ago
onebnj.com
1bnjwin.com
1bnjgame.com
ambfatthai.com
ambfatth.com
Project: d346d18a-c3cc-4bb2-84fb-4a25cad62fbf
bjesus
Same issue on online.haprofessor.com , hundreds of users cannot login in and we're in the middle of a presentation. Tried deleting and readding the domain, didn't help.
24 days ago
Mitigations applied
Status changed to Awaiting User Response Railway • 24 days ago
24 days ago
www.pvpscalpel.com
pvpscalpel.com ( general )
api.pvpscalpel.com
Error:
=> 421 Misdirected Request
=> Requested host does not match any Subject Alternative Names (SANs) on TLS certificate
Impact:
=> Main website down
=> API unreachable
=> Desktop client failing to connect
Setup:
=> Custom domain behind Cloudflare
=> DNS resolving correctly
=> curl confirms Cloudflare IPs
=> Response headers show: x-served-by: cache-sof...
This appears to be a Metal Edge / certificate binding issue rather than a DNS misconfiguration.
Status changed to Awaiting Railway Response Railway • 24 days ago
lstanev00
www.pvpscalpel.compvpscalpel.com ( general )api.pvpscalpel.comError:=> 421 Misdirected Request=> Requested host does not match any Subject Alternative Names (SANs) on TLS certificateImpact:=> Main website down=> API unreachable=> Desktop client failing to connectSetup:=> Custom domain behind Cloudflare=> DNS resolving correctly=> curl confirms Cloudflare IPs=> Response headers show: x-served-by: cache-sof...This appears to be a Metal Edge / certificate binding issue rather than a DNS misconfiguration.
24 days ago
fixed*
24 days ago
Update from the network engineering team, the script is running we should see widespread restoration.
Status changed to Awaiting User Response Railway • 24 days ago
24 days ago
Three more domains if you can please work your magic...
stockman.bst.co.nz
Interestingly, it's only 'cusotm' subdomains that are impacted for us - admin. breaks but www. doesn't on a number of domains.
(note these domains won't be accessible for you either due to Firewall)
Status changed to Awaiting Railway Response Railway • 24 days ago
brody
Both domains are working for us.
24 days ago
I am trying to reach https://fundchamps.teamfundraising.org/ and it uses the underlying wildcard subdomain, i.e. *.teamfundraising.org and it isn't working. Still says SSL handshake failed Error code 525.
On railway, as I turned off the proxy, it now says Validating domain ownership. Any idea on how long this takes? Should I change something
24 days ago
It's finally working now. I turned off the proxy in Railway as per the documentation here: https://docs.railway.com/networking/troubleshooting/ssl#error-525-ssl-handshake-failed
rjbathgate
Three more domains if you can please work your magic...admin.theloft.legalstockman.bst.co.nzInterestingly, it's only 'cusotm' subdomains that are impacted for us - admin. breaks but www. doesn't on a number of domains.(note these domains won't be accessible for you either due to Firewall)
24 days ago
Mitigations applied
Status changed to Awaiting User Response Railway • 24 days ago
lstanev00
www.pvpscalpel.compvpscalpel.com ( general )api.pvpscalpel.comError:=> 421 Misdirected Request=> Requested host does not match any Subject Alternative Names (SANs) on TLS certificateImpact:=> Main website down=> API unreachable=> Desktop client failing to connectSetup:=> Custom domain behind Cloudflare=> DNS resolving correctly=> curl confirms Cloudflare IPs=> Response headers show: x-served-by: cache-sof...This appears to be a Metal Edge / certificate binding issue rather than a DNS misconfiguration.
24 days ago
Mitigations applied
parsilver
onebnj.com1bnjwin.com1bnjgame.comambfatthai.comambfatth.comProject: d346d18a-c3cc-4bb2-84fb-4a25cad62fbf
24 days ago
Mitigations applied
exilent-vij
Same issue on wonderboo.funa92be7db-43ea-4571-afca-a96a7394891e
24 days ago
Mitgations applied
24 days ago
i solved this by:
1. go to cloudflare domain (or other)
2. find DNS records which are using IP address as target value on A record
remove them
and resolved.
Status changed to Awaiting Railway Response Railway • 24 days ago
abeshunyah
i solved this by:1. go to cloudflare domain (or other)2. find DNS records which are using IP address as target value on A recordremove themand resolved.
24 days ago
Yes, and for the record, this was never a supported configuration.
Status changed to Awaiting User Response Railway • 24 days ago
24 days ago
Network engineer is reporting that we fully backfilled. However, we are going to keep the incident up until we have confirmed that all domains that should get the SSL ACME challenge indeed got it.
The other thing here is as a result of this change, we have tightened how we have issued certs so we are going to work with those with misconfigured domains, expect an email from us.
What's the best way to tell if this is affecting our service? I am having weird issues from https -> http redirects and I can't tell if it's this or something else that's messed up.
24 days ago
domain?
my problem is likely related to the other thread: https://discord.com/channels/713503345364697088/1474453531825012838/1474453531825012838
24 days ago
yes, its that issue
Status changed to Solved brody • 23 days ago








