Certificate problem.
vqh75vuz6dkjz5
PROOP

21 days ago

I have two custom domains on my web service that show VALID CNAME status but SSL certificates are not being issued. Both domains serve the *.up.railway.app wildcard cert instead of a dedicated cert, causing

  ERR_CERT_COMMON_NAME_INVALID in browsers.

  Project ID: 1a7515d3-9a14-44b3-afb5-50bb71c868b6

  Service ID: 948d9784-da5b-4ad6-ac71-a1baaffe02d5

  Environment ID: cc514c6a-9c84-48be-8369-21364c4d1050

  Service domain: web-production-64d16.up.railway.app

  Affected domains:

  - shop.acx.dk — CNAME → web-production-64d16.up.railway.app (DNS only, no Cloudflare proxy) — VALID for 24+ hours, no cert

  - store.acx.dk — same setup — VALID for several hours, no cert

  What I've verified:

  - DNS resolves correctly: shop.acx.dkweb-production-64d16.up.railway.app → 66.33.22.254

  - HTTP port 80 is reachable (Railway edge responds with Server: railway-edge)

  - No CAA records blocking Let's Encrypt

  - No DNSSEC enabled

  - Cloudflare proxy is OFF (DNS only / grey cloud)

  - Other custom domains on the same service (bikie.io, shops.bikie.io) have valid certs

  What may have caused the issue:

  During initial setup, the CNAME was briefly misconfigured. While troubleshooting, the shop.acx.dk domain was deleted and re-added via the API approximately 4-5 times, which may have triggered Let's Encrypt rate

  limiting.

  Could you check if cert issuance is stuck or rate-limited for these domains, and help unstick it? Thank you.

$20 Bounty

9 Replies

Railway
BOT

21 days ago

This thread has been marked as public for community involvement, as it does not contain any sensitive or personal information. Any further activity in this thread will be visible to everyone.

Status changed to Open Railway 21 days ago


Did you add all DNS records railway shows, not just the main CNAME for all domains.?.
for shop.acx.dk and store.acx.dk, make sure there is only the intended CNAME (and no A/AAAA at the same name). As a temporary workaround, you could enable cloudflare proxy ...so visitors get a valid cert at the edge while railway origin SSL finishes provisioning


vqh75vuz6dkjz5
PROOP

21 days ago

Railway does not finish provisioning.


vqh75vuz6dkjz5
PROOP

21 days ago

Not sure why Railway made this public. It is an error on their end.

Railway team -
shop.acx.dk is registered as custom domains on service "web" in project BIKIE (production). Both show "Domain is in use by service web in project BIKIE" when I try to re-add them. But both return x-railway-fallback: true 404s. The domains are registered but your edge isn't routing traffic to my service. Can you check the edge routing for these domains?


21 days ago

Made this public, as the issue is not on our end. You have not set up your domains correctly.

shop.acx.dk is not currently attached to a Railway service, and store.acx.dk has an incorrect DNS setup.


vqh75vuz6dkjz5
PROOP

21 days ago

Not currently, because I am trying all kinds of workarounds. I don't know what you're looking at now, but it most definitely isn't issuing a cert. I have managed to get webshop.acx.dk working by enabling Cloudflare proxy to handle SSL, because Railway never issued a certificate for it despite the domain being correctly registered and CNAME verified for hours. The same happened with shop.acx.dk. It was attached to our service, CNAME was valid, and your dashboard confirmed it, but no cert was ever issued.

I only removed it after hours of it not working. If this is "not set up correctly," please tell me specifically what was wrong, because from our side everything was configured exactly as documented.


vqh75vuz6dkjz5
PROOP

21 days ago

Just read my message and realized i sound sour as hell. Didn't mean to be passive aggressive, I am just confused after a long day dealing with this.


21 days ago

No worries at all, I just wanted to clarify why this was made public for community involvement.

Once you remove and add the domains with the correct configurations, our infra will be able to issue the certificates.


vqh75vuz6dkjz5
PROOP

21 days ago

Can I somehow PM you Brody? It's not that I do not want to contribute to your knowledge base and/or community, but I am a very private person, and I am not super comfortable about the thread being public.


20 days ago

I'm really sorry, but we are not able to offer assistance here, as this thread does not pertain to an issue with our platform or product. It's simply an incorrect domain setup. Since it's not an issue on our end, that means the community is the path to get support, so I will disengage from this thread and let the community continue to assist you.


Loading...