Custom domain lumiere.ai.kr - Let's Encrypt cert never auto-renewed, expires 2026-08-27
seunghyeog161-wq
PROOP

10 days ago

My custom domain's Let's Encrypt certificate has never been renewed and expires on 2026-08-27. Per your docs, renewal should begin at 30 days remaining (around 2026-07-28), but no new certificate has ever been issued for this domain.

Project: LUMIERE - 7546d8ab-992c-4a10-b9f2-c87359474b70

Service: lumiere-backend - 0a7ff9ca-7942-4266-bba9-871caee171f2

Environment: 87a73b9b-46cd-46bc-a7b1-ca2cfcef0cb4

Custom domain: lumiere.ai.kr (port 8080), shows a green check in Settings / Networking

Plan: Pro

  1. Certificate currently served on lumiere.ai.kr (measured 2026-08-11):

issuer = C=US, O=Let's Encrypt, CN=YE1

notBefore = May 29 06:27:50 2026 GMT

notAfter = Aug 27 06:27:49 2026 GMT

serial = 05D92F804FE8EC2D22CFB20A74C168E7DE3E

This is still the original certificate from first issuance.

  1. Railway's own wildcard on the same edge DID renew on schedule:

lumiere-backend-production-ccd0.up.railway.app

notBefore = Jul 29 02:40:55 2026 GMT

notAfter = Oct 27 02:40:54 2026 GMT

serial = 06DA79BB561DA3EFEB0E751CA21ABD3999FE

That is a renewal on Jul 29, 29 days before an Aug 27 expiry, exactly what the 30-day policy predicts. So the ACME machinery is alive; the custom domain looks like it was skipped by it.

  1. Certificate Transparency logs show no issuance for lumiere.ai.kr since 2026-05-29 (checked via Cert Spotter). Only three entries exist in total: one unrelated Sectigo certificate (2026-05-24, not served by Railway) and the precert/leaf pair of the Let's Encrypt certificate above. So there is no already-issued renewal waiting to be deployed, it was never issued at all.

  2. I ruled out every cause listed in your SSL troubleshooting docs:

DNS: lumiere.ai.kr A resolves to 66.33.22.145, correctly

CAA: no CAA records on lumiere.ai.kr or on the parent zone ai.kr (NODATA on both)

DNSSEC: zone is not signed (AD=false)

Cloudflare: not proxied, direct to the Railway edge

The domain shows as verified (green) in the dashboard

Could you re-trigger issuance for this domain from your side?

I would rather not delete and re-add the domain, since your docs warn about Let's Encrypt rate limits and I want to avoid downtime. This domain is the landing page for an ad campaign that may begin delivering any day, so an outage during re-issuance would spend budget against an unreachable page.

In Progress

2 Replies

Status changed to Awaiting Railway Response Railway 10 days ago


dizzydes90
EMPLOYEE

10 days ago

Hi, quick update. The certificate for lumiere.ai.kr didn't get picked up by our automatic renewal, and the fix needs a change from our platform team.

Your current certificate is valid through August 27, so the site keeps working normally in the meantime and there's nothing you need to change. I'm following up with the platform team to get a fresh certificate issued well before that date, and I'll reply here as soon as it's live.

Thanks for your patience, and for the really thorough report.

Des


Status changed to Awaiting User Response Railway 10 days ago


Status changed to In Progress dizzydes90 10 days ago


dizzydes90
EMPLOYEE

10 days ago

We're posting a fix for this internally and then will regenerate your ECDSA cert in the coming hours.

Also can you point your CNAME to us in your DNS settings? There complications without.


Welcome!

Sign in to your Railway account to join the conversation.

Loading...