Custom domain certificate issuance fails for tib-tan.org despite verified DNS
faizsfoan-ops
HOBBYOP

a month ago

The custom domain tib-tan.org is verified and its traffic CNAME matches the Railway-provided target.

Railway reports:

  • certificate status: ISSUE_FAILED
  • error type: INTERNAL
  • certificate retryable: true

I ran one official certificate retry, but the status remained failed. TLS with SNI tib-tan.org still presents Railway's default *.up.railway.app certificate, causing NET::ERR_CERT_COMMON_NAME_INVALID.

The service is deployed and healthy through its Railway-provided domain. No restrictive CAA record or DNSSEC delegation is present.

Could you please investigate certificate issuance for tib-tan.org and re-issue the certificate from Railway's side?

Solved

3 Replies

Status changed to Awaiting Railway Response Railway • about 1 month ago


a month ago

Your DNS and domain verification are correctly configured, and we've started a certificate re-issuance for that domain. It may take a few minutes to complete, after which the TLS certificate should serve correctly and the NET::ERR_CERT_COMMON_NAME_INVALID error should resolve.


Status changed to Awaiting User Response brody • about 1 month ago


brody

Your DNS and domain verification are correctly configured, and we've started a certificate re-issuance for that domain. It may take a few minutes to complete, after which the TLS certificate should serve correctly and the `NET::ERR_CERT_COMMON_NAME_INVALID` error should resolve.

faizsfoan-ops
HOBBYOP

a month ago

Thank you. It has now been about two hours since the certificate re-issuance was started, but https://tib-tan.org is still returning:

NET::ERR_CERT_COMMON_NAME_INVALID

Could you please check the current certificate issuance status and confirm whether the re-issuance completed successfully or if it is still failing internally?

I have not changed the DNS configuration since your last message.


Status changed to Awaiting Railway Response Railway • about 1 month ago


Railway
BOT

a month ago

The certificate re-issuance was triggered but has not completed because traffic to the domain is arriving through a proxy (our edge sees it served by Cloudflare rather than reaching us directly), which can prevent HTTP-based certificate validation from succeeding. Our SSL troubleshooting docs and Cloudflare configuration guide cover the required settings when a domain is proxied through Cloudflare, including setting SSL/TLS mode to Full (not Full Strict) and ensuring Universal SSL is enabled.


Status changed to Awaiting User Response Railway • about 1 month ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...