a month ago
Hi,
A custom domain on my project has been stuck without a certificate since July 30,
about four weeks now. The app itself works fine on its *.up.railway.app domain.
Project: 3e8cb0e7-4686-4d9f-ab71-0b93f2988d32
Service: 326f368e-e40e-4026-bbf9-613f95f5dc6d (web)
Environment: 4def6e14-490a-493e-b33b-3d2701baab24 (production)
Domain: automacao.eugeniomartins.com.br
Domain ID: 85180f65-5c7a-4d1b-b73c-7c59a4411fbd
Current state (from your own API):
- certificateStatus: CERTIFICATE_STATUS_TYPE_ISSUING
- DNS record: DNS_RECORD_STATUS_PROPAGATED
- requiredValue and currentValue both = tn3i7y85.up.railway.app
What I have already verified and ruled out:
-
CNAME is correct and propagated worldwide (confirmed via public resolvers and by
your API reporting PROPAGATED).
-
No CAA records on the apex domain, and no DNSSEC, so nothing is blocking
Let's Encrypt issuance.
-
Port 80 reaches your edge normally (HTTP returns 301), so the ACME HTTP path
is reachable.
-
HTTPS with certificate verification disabled returns 404 and serves the
*.up.railway.app wildcard certificate, so the hostname appears never to get
attached at the edge.
-
I deleted and recreated the custom domain three times, updating the CNAME to the
new target each time, and triggered customDomainIssueCertificate several times.
It moved from VALIDATING_OWNERSHIP to ISSUING and has stayed there since.
-
Verified from two independent networks, so it is not a local DNS cache issue.
It looks like this hostname is wedged in your control plane. Could you please clear
the stuck state and re-trigger issuance?
Note: I also created painel.eugeniomartins.com.br (ID
2125335e-2d40-45ee-ba84-9941fc460041) as a diagnostic and never pointed its DNS.
Please feel free to delete that one.
Thanks!
1 Replies
a month ago
The domain's certificate is stuck because ownership verification has not completed - verified is currently false. The CNAME for traffic routing is correctly propagated, but there is no TXT record at the verification hostname (_railway-verify. prefix on the domain). Adding a TXT record there with the verification value shown in your service's Settings under Networking will allow verification to complete and the certificate to issue.
Status changed to Awaiting User Response Railway • about 1 month ago
a month ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • about 1 month ago