a month ago
Hi,
Two custom domains on our production service have been stuck in certificate validation for 44 hours and the ACME order never seems to start.
Project / service
- Project: Vitala (project id 7af64dd6-9f78-42d0-a30d-3c688d726eec)
- Service: vitala (service id d1844871-bb8e-4e8d-89e3-0ab3e70fb583)
- Environment: production (8175c630-8cb4-4ce6-ab62-3b7e405550d6)
- The service itself is healthy and serving traffic fine on vitala-production.up.railway.app.
The two domains
- vitalayogastudio.mx (domain id 96a408f2-6fbf-4228-bb8b-70aad34b13e2), target port 8080, created 2026-09-05T22:09:49Z
- www.vitalayogastudio.mx (domain id a90efbae-822f-4ae6-b9c8-08979eafc7aa), target port 8080, created 2026-09-05T22:09:50Z
What your API reports for both, as of 2026-09-07T18:06:11Z
- certificateStatus: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSH
- certificateStatusDetailed: null
- DNS records: DNS_RECORD_STATUS_PROPAGATED on both, purpose DNTE
- No error message anywhere in the response
Because the detailed status has been null the whole time, it looks like the certificate order was never created on your side, rather than an order that is
failing validation against our DNS.
What we checked on our side, and ruled out
- DNS resolves to the hostnames you asked for. Root resolves to the address behind kgkbiwjc.up.railway.app (69.46.46.69) and www is a CNAME to f6lm93zv.up.railway.app (69.46.46.7). Both records are DNS-only
- No CAA records anywhere in the zone (queried directly against the authoritative nameservers).
- No DNSSEC on the domain, no DS record in the .mx zone.
- The certificate does not exist on any of your edge addresses. Asking for the domain by name over TLS returns your default wildcard, CN=*.up.railway.app,
issued by Let's Encrypt, valid Jul 29 2026 to Oct 27 2026.
- We already removed and re-added both domains once, on 2026-09-05 at 22:09 UTC. That produced new CNAME targets, which we updated in Cloudflare, and the
status did not change.
What we are asking for
Could you look at why the ACME order is not being created for these two domains, or re-trigger issuance on your side? We would rather not remove and re-add them again, because every re-add changes the CNAME targets we h.
Thanks.
1 Replies
Status changed to Awaiting Railway Response Railway • 28 days ago
a month ago
Both domains are live now. Certificates are valid, DNS is propagated, and both are returning 200 through our edge. The issuance pipeline completed since you posted.
Status changed to Awaiting User Response Railway • 28 days ago
Status changed to Solved brody • 28 days ago