Custom domain TLS stuck on “Issuing TLS certificate” despite verified DNS
mcompton1990-afk
HOBBYOP

2 months ago

Custom domain TLS stuck on “Issuing TLS certificate” despite verified DNS

Project: honest-gratitude

Service: Marker_Muse_Web

Environment: production

Domain: markermuse.app

The custom domain has been stuck on “Issuing TLS certificate” for over 1 hour.

Troubleshooting completed:

markermuse.app resolves to 69.46.46.6

Railway target zed4tvba.up.railway.app resolves to the same 69.46.46.6

Google DNS and Cloudflare DNS both return the same result

no AAAA record exists

_railway-verify.markermuse.app TXT is present on both resolvers

no CAA record is present

DNSSEC lookup returns cleanly, no SERVFAIL

HTTP on port 80 reaches Railway and returns 301 to https://markermuse.app/

TLS on port 443 connects, but Railway is serving *.up.railway.app

TLS authorization fails with ERR_TLS_CERT_ALTNAME_INVALID

Railway-generated web domain is healthy and returns HTTP 200

backend health endpoint returns HTTP 200

Railway dashboard still shows markermuse.app → Issuing TLS certificate.

We have not deleted/re-added the domain because Railway documentation warns against repeated certificate reissuance attempts.

Please check whether certificate provisioning for this custom domain is stuck at Railway’s edge/provisioning layer.

Solved

1 Replies

Status changed to Awaiting Railway Response Railway • about 2 months ago


2 months ago

Your DNS is configured correctly and the domain is verified, but the certificate issuance workflow stalled. We've re-triggered certificate issuance for markermuse.app, which may take a few minutes to complete.


Status changed to Awaiting User Response brody • about 2 months ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...