Failed to issue TLS certificate
thebigdaddydev
PROOP

2 months ago

I'm having issues on some of my domains

nexvialogs.com

abidalhub.com

monarchlogs.com

backuplogs.com

sanchexhub.com

the www.domainname.com has resolved properly but trying to add the domain alone so it can also have its certificate but it's having an error of "Failed to issue TLS certificate "

Solved

5 Replies

Status changed to Awaiting Railway Response Railway • about 2 months ago


2 months ago

Your DNS is correctly configured and verified on all five domains. Certificate issuance hit an internal error on our side, so we're re-triggering it for all of them now. The certificates should come through within a few minutes.


Status changed to Awaiting User Response Railway • about 2 months ago


thebigdaddydev
PROOP

2 months ago

YET TO WORK


Status changed to Awaiting Railway Response Railway • about 2 months ago


2 months ago

We've re-checked all five domains. Four are stuck mid-issuance and we're re-triggering their certificates now. The fifth (monarchlogs.com) hit a persistent internal error that requires a separate manual fix on our end, which we're also addressing. The certificates should come through within a few minutes once the re-triggers complete.


Status changed to Awaiting User Response Railway • about 2 months ago


Railway
BOT

2 months ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 2 months ago


thebigdaddydev
PROOP

a month ago

FOR 10 days still issuing TLS


Status changed to Awaiting Railway Response Railway • about 1 month ago


sam-a
EMPLOYEE

a month ago

I'm sorry this has dragged on for two weeks. You were told twice that your DNS was correctly configured and that we were re-triggering the certificates. That was wrong, and re-triggering was never going to fix it. Our check looks for the CNAME record, finds it, and reports everything as healthy, so it missed the actual problem. That's on us, and it's why you kept getting the same answer with no result.

It turns out there's a configuration problem on the domains themselves.

The www versions work because they only have a CNAME record pointing at Railway. The apex versions (nexvialogs.com, abidalhub.com, monarchlogs.com, backuplogs.com, sanchexhub.com) each have a second, conflicting record: an A record left over from Namecheap's parking page, sitting alongside the CNAME.

A domain can't have both. When both exist, the apex sometimes resolves to Namecheap's parking IP instead of Railway. The certificate authority's ownership check then lands on the parking page rather than your service, the check fails, and issuance stalls indefinitely. That's the state all five have been in.

To fix it, in Namecheap for each of the five domains:

  1. Go to Domain List, then Manage, then Advanced DNS.
  2. Delete the A record on host @ (it points to a Namecheap IP). Also remove any URL Redirect or parking record on @.
  3. Leave the CNAME record on @ in place, pointing to the target shown for that domain in your Railway dashboard.

Once the A records are gone, DNS needs up to an hour to update. The certificates should then issue on their own. Let us know when you've made the change and we'll confirm from our side.


Status changed to Awaiting User Response Railway • about 1 month ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...