Custom domain SSL cert stuck at VALIDATING_OWNERSHIP
markwadden-boop
HOBBYOP

2 months ago

Domain app.foundryevolux.com on project courageous-unity, service web. DNS fully propagated — CNAME ugun4bx1.up.railway.app verified on Google DNS and Cloudflare. Railway shows DNS_RECORD_STATUS_PROPAGATED but cert stuck at CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP for 4+ hours. Domain ID: fa7d4a13-d543-425c-9a5f-01ac8b5b2cca. Please trigger cert provisioning manually.

Solved$10 Bounty

4 Replies

Railway
BOT

2 months ago

Your domain is missing the required TXT verification record. You need to add a TXT record with host _railway-verify.app and value railway-verify=eea956e2008ac40f0c3548649b9876afe6151a9a0f8f0fde566debdc261e8ef4 at your DNS provider. The certificate will not issue until this ownership verification record is in place alongside the CNAME.


Railway
BOT

2 months ago

This thread has been marked as private. Any further activity in this thread will only be visible to you and Railway employees.

Status changed to Awaiting User Response Railway about 2 months ago


Railway

Your domain is missing the required TXT verification record. You need to add a TXT record with host `_railway-verify.app` and value `railway-verify=eea956e2008ac40f0c3548649b9876afe6151a9a0f8f0fde566debdc261e8ef4` at your DNS provider. The certificate will not issue until this ownership verification record is in place alongside the CNAME.

markwadden-boop
HOBBYOP

2 months ago

The TXT record IS present. Google DNS confirms it: _railway.app.foundryevolux.com TXT railway-verify=eea956e2008ac40f0c3548649b9876afe6151a9a0f8f0fde566debdc261e8ef4. Both CNAME and TXT records are verified and propagated. The issue is Railway's cert provisioner is stuck at CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP despite DNS being correct on all resolvers. Please manually trigger cert issuance for Domain ID: fa7d4a13-d543-425c-9a5f-01ac8b5b2cca


Status changed to Awaiting Railway Response Railway about 2 months ago


Railway
BOT

2 months ago

This thread has been marked as public for community involvement, as it does not contain any sensitive or personal information. Any further activity in this thread will be visible to everyone.

Status changed to Open Railway about 2 months ago


godmodgamerz
HOBBY

2 months ago

Try updating all values and issuing a SSL certificate

This mainly Causes this issue


2 months ago

Hey, I just did a nslookup on your domain app.foundryevolux.com and I don't see the TXT record there, you are placing the TXT record under the _railway.app.foundryevolux.com subdomain which is incorrect.


Status changed to Solved medim 23 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...