21 days ago
I have two custom domains on my web service that show VALID CNAME status but SSL certificates are not being issued. Both domains serve the *.up.railway.app wildcard cert instead of a dedicated cert, causing
ERR_CERT_COMMON_NAME_INVALID in browsers.
Project ID: 1a7515d3-9a14-44b3-afb5-50bb71c868b6
Service ID: 948d9784-da5b-4ad6-ac71-a1baaffe02d5
Environment ID: cc514c6a-9c84-48be-8369-21364c4d1050
Service domain: web-production-64d16.up.railway.app
Affected domains:
- shop.acx.dk — CNAME → web-production-64d16.up.railway.app (DNS only, no Cloudflare proxy) — VALID for 24+ hours, no cert
- store.acx.dk — same setup — VALID for several hours, no cert
What I've verified:
- DNS resolves correctly: shop.acx.dk → web-production-64d16.up.railway.app → 66.33.22.254
- HTTP port 80 is reachable (Railway edge responds with Server: railway-edge)
- No CAA records blocking Let's Encrypt
- No DNSSEC enabled
- Cloudflare proxy is OFF (DNS only / grey cloud)
- Other custom domains on the same service (bikie.io, shops.bikie.io) have valid certs
What may have caused the issue:
During initial setup, the CNAME was briefly misconfigured. While troubleshooting, the shop.acx.dk domain was deleted and re-added via the API approximately 4-5 times, which may have triggered Let's Encrypt rate
limiting.
Could you check if cert issuance is stuck or rate-limited for these domains, and help unstick it? Thank you.
9 Replies
21 days ago
This thread has been marked as public for community involvement, as it does not contain any sensitive or personal information. Any further activity in this thread will be visible to everyone.
Status changed to Open Railway • 21 days ago
21 days ago
Did you add all DNS records railway shows, not just the main CNAME for all domains.?.
for shop.acx.dk and store.acx.dk, make sure there is only the intended CNAME (and no A/AAAA at the same name). As a temporary workaround, you could enable cloudflare proxy ...so visitors get a valid cert at the edge while railway origin SSL finishes provisioning
21 days ago
Railway does not finish provisioning.
21 days ago
Not sure why Railway made this public. It is an error on their end.
Railway team -
shop.acx.dk is registered as custom domains on service "web" in project BIKIE (production). Both show "Domain is in use by service web in project BIKIE" when I try to re-add them. But both return x-railway-fallback: true 404s. The domains are registered but your edge isn't routing traffic to my service. Can you check the edge routing for these domains?
21 days ago
Made this public, as the issue is not on our end. You have not set up your domains correctly.
shop.acx.dk is not currently attached to a Railway service, and store.acx.dk has an incorrect DNS setup.
21 days ago
Not currently, because I am trying all kinds of workarounds. I don't know what you're looking at now, but it most definitely isn't issuing a cert. I have managed to get webshop.acx.dk working by enabling Cloudflare proxy to handle SSL, because Railway never issued a certificate for it despite the domain being correctly registered and CNAME verified for hours. The same happened with shop.acx.dk. It was attached to our service, CNAME was valid, and your dashboard confirmed it, but no cert was ever issued.
I only removed it after hours of it not working. If this is "not set up correctly," please tell me specifically what was wrong, because from our side everything was configured exactly as documented.
21 days ago
Just read my message and realized i sound sour as hell. Didn't mean to be passive aggressive, I am just confused after a long day dealing with this.
21 days ago
No worries at all, I just wanted to clarify why this was made public for community involvement.
Once you remove and add the domains with the correct configurations, our infra will be able to issue the certificates.
21 days ago
Can I somehow PM you Brody? It's not that I do not want to contribute to your knowledge base and/or community, but I am a very private person, and I am not super comfortable about the thread being public.
20 days ago
I'm really sorry, but we are not able to offer assistance here, as this thread does not pertain to an issue with our platform or product. It's simply an incorrect domain setup. Since it's not an issue on our end, that means the community is the path to get support, so I will disengage from this thread and let the community continue to assist you.