Custom domain cert not provisioning.
vnjv175
HOBBYOP

17 days ago

Project bb5a8a69, service 35917601, domain backend.dmcaguardian.xyz. CNAME is VALID, HTTP ACME intercept works (returns 404), but no cert issued after 2+ hours. Tried multiple domains (api.dmcaguardian.xyz, backend.dmcaguardian.xyz). Same result on fresh subdomains.

Solved

11 Replies

You need to add TXT records to _railway-verify. backend.dmcaguardian.xyz and _railway-verify.api.dmcaguardian.xyz.


You can find the content for the TXT records under verificationToken property under status.


vnjv175
HOBBYOP

17 days ago

What values should the TXT records contain?


Are you using the API?


vnjv175
HOBBYOP

16 days ago

Yes, adding domains via the GraphQL API (customDomainCreate mutation). Should we use the dashboard instead?


You can obtain the TXT content from the verificationToken property under status.


Either works.


vnjv175
HOBBYOP

16 days ago

Added the TXT record for _railway-verify.backend.dmcaguardian.xyz with value railway-verify=2b1f2a07efabe39c3dbf5e608e622a2412e7356606c2e42d567b414fbb85699f.

Can you trigger cert provisioning for backend.dmcaguardian.xyz on service 35917601-2da2-48a6-8d3b-879316738feb?

CNAME is valid and pointing to api-production-b2ee.up.railway.app.


Railway should automatically trigger the certs after detecting the DNS changes.

Also, keep in mind that the CNAME records should be pointing to the provided CNAME content by Railway, it shouldn't be pointing to the pregenerated domain.


(If Railway doesn't automatically issue the cert within the hour, remove the domain from Railway, wait for ~10-15 mins, then re-add the domain. Make sure to update DNS records as necessary.)


vnjv175
HOBBYOP

16 days ago

i believe its resolved now, thanks


Status changed to Solved 0x5b62656e5d 16 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...