a month ago
Custom domain book.23amblesideretreat.co.za is stuck on "Waiting for DNS update" for the TXT record. Both records are correct and confirmed authoritative on all four of the zone's nameservers (ns1/ns3.tld-ns.net, ns2/ns4.tld-ns.com) — my registrar supplied dig output against each. The value matches exactly: railway-verify=4f833895c6b02255fdc9b76ab1e6b584e96c2d8fb0c11f9d8f7136008c30aae7. The zone was re-published today (SOA serial 2026090401). There had been an inconsistency under the previous serial, so I suspect a cached negative on your side. Could you force a re-verification without regenerating the token? Project efficient-warmth, service Booking-manager.
3 Replies
Status changed to Awaiting Railway Response Railway • about 1 month ago
a month ago
Your DNS records are correct: the CNAME is propagated and the TXT verification token at _railway-verify.book.23amblesideretreat.co.za matches exactly. The verification workflow stalled while the earlier DNS inconsistency was in place and never re-ran after your fix. We have started a certificate re-issuance for this domain, which should complete within a few minutes.
Status changed to Awaiting User Response brody • about 1 month ago
brody
Your DNS records are correct: the CNAME is propagated and the TXT verification token at `_railway-verify.book.23amblesideretreat.co.za` matches exactly. The verification workflow stalled while the earlier DNS inconsistency was in place and never re-ran after your fix. We have started a certificate re-issuance for this domain, which should complete within a few minutes.
a month ago
The domain is still serving your platform's default certificate, not one for our domain.
Certificate presented at book.23amblesideretreat.co.za:
Subject CN: *.up.railway.app
Subject Alt Names: *.up.railway.app, up.railway.app
Issuer: Let's Encrypt YE1
Valid: 29 Jul 2026 – 27 Oct 2026
Serial: 06:DA:79:BB:56:1D:A3:EF:EB:0E:75:1C:A2:1A:BD:39:99:FE
No SAN covers book.23amblesideretreat.co.za, so browsers report a domain mismatch and refuse the connection. The validity dates show this certificate predates the re-issuance you began today by several weeks — so no new certificate has been issued or deployed for our domain.
Please confirm the status of the ACME order for this domain and whether validation failed. Our DNS is confirmed correct on your side, and there are no CAA records on the zone restricting issuance.
Status changed to Awaiting Railway Response Railway • about 1 month ago
a month ago
The certificate re-issuance has completed successfully: the domain is now verified, the certificate status is valid, and edge routing is responding normally (HTTP 200). The *.up.railway.app wildcard certificate you observed was served from a cached TLS session before the new certificate finished deploying. If your browser still shows the mismatch, close all tabs to that domain and reconnect, or test in an incognito window, so a fresh TLS handshake picks up the new certificate.
Status changed to Awaiting User Response Railway • about 1 month ago
Status changed to Solved 23ambleside • about 1 month ago