20 days ago
Hi,
the custom domain sigeko-command.de has been stuck in ISSUING since 29 Aug 2026 (17 days). HTTPS on that hostname still serves the shared *.up.railway.app wildcard certificate, so browsers show a certificate error.
The apex sits on the same service as app.sigeko-command.de, which was issued and renewed without any problem (current cert valid 4 Sep – 3 Dec 2026).
What I verified today (15 Sep 2026):
- Your API reports the domain as
verified: true, DNS recordPROPAGATED, certificateISSUING, witherrorMessage: nullandretryable: null. - The target you require is
k5tf62hk.up.railway.app, which resolves to 69.46.46.60. Our apex resolves to exactly that IP (ALIAS record at our registrar INWX, since CNAME is not allowed at an apex). No AAAA record. - That IP is your edge: a request to 69.46.46.60 with
Host: app.sigeko-command.dereturns 200, so routing reaches Railway. - There are no CAA records on the domain, so Let's Encrypt is not being blocked that way.
http://sigeko-command.de/.well-known/acme-challenge/<token>returns 404 from your edge, not from our app (our middleware would answer 401 for an unknown path), which suggests no ACME challenge is currently being attempted.
Project Sigeko (36a5962c-ee53-4215-81ee-45e2c1bea570), service sigeko-command-center (7fa2ccb7-0bbb-49a0-a263-af3579eae766), environment production, domain ID df3ce69e-3a69-4a22-a47c-957dda4e03e9.
Could you check why the ACME order for the apex never completes, and re-trigger issuance on your side? I have deliberately not deleted and re-added the domain to avoid the Let's Encrypt rate limit.
Thanks!
2 Replies
Status changed to Awaiting Railway Response Railway • 20 days ago
20 days ago
We confirmed the domain is verified and the ACME HTTP-01 challenge reaches our edge, so nothing on your side is blocking issuance. Certificate issuance for the apex has been restarted and may take a few minutes.
Status changed to Awaiting User Response brody • 20 days ago
20 days ago
Resolved, thank you. After the restart the apex certificate was issued: your API now reports the domain as VALID, and TLS on sigeko-command.de serves CN=sigeko-command.de (Let's Encrypt, valid 15 Sep - 14 Dec 2026). https://sigeko-command.de now redirects to our app as intended. For anyone finding this later: the domain sat in ISSUING for 18 days with verified: true, DNS PROPAGATED and errorMessage: null, and nothing on our side changed - support had to re-trigger issuance.
Status changed to Awaiting Railway Response Railway • 20 days ago
Status changed to Solved Railway • 20 days ago