a month ago
The wildcard domain *.flexops.com.ar is stuck in validation with error "Failed to issue TLS certificate - Internal error". The apex domain flexops.com.ar validates successfully, but the wildcard never completed validation.
PROJECT DETAILS:
- Project ID: 8d493a81-d10b-450c-bcb2-7d214c389a9d
- Service: FlexOps
- Environment: production
TIMELINE:
- Added wildcard domain *.flexops.com.ar to the service
- Apex domain flexops.com.ar validated successfully (Verified: yes)
- Wildcard remained stuck in validation
- CNAME targets regenerated 10 minutes ago (z5licbl1 targets)
- Now shows: "Failed to issue TLS certificate - Internal error"
CURRENT DNS:
- _acme-challenge.flexops.com.ar CNAME → z5licbl1.authorize.railwaydns.net
- *.flexops.com.ar CNAME → z5licbl1.up.railway.app
- flexops.com.ar CNAME → 3d4tuv6u.up.railway.app (Verified: yes)
All records are DNS only and configured correctly. The apex validates but the wildcard fails with an internal error. Needs investigation.
3 Replies
a month ago
Your wildcard certificate is failing because your DNS provider is serving stale, cached ACME challenge values instead of letting the certificate authority follow the CNAME delegation to read the current token. This makes every issuance attempt fail identically, even though your DNS records look correct from a normal lookup. To fix this, delete the ACME challenge CNAME record at your DNS provider, wait a minute or two, then recreate it using the same value shown in your Railway dashboard for that domain.
Status changed to Awaiting User Response Railway • about 2 months ago
Railway
Your wildcard certificate is failing because your DNS provider is serving stale, cached ACME challenge values instead of letting the certificate authority follow the CNAME delegation to read the current token. This makes every issuance attempt fail identically, even though your DNS records look correct from a normal lookup. To fix this, delete the ACME challenge CNAME record at your DNS provider, wait a minute or two, then recreate it using the same value shown in your Railway dashboard for that domain.
a month ago
I did everything in the answer but still getting Failed to issue TLS certificate
Try Again
An internal error occurred. Please retry or contact support. , I almost delete both domains, all the CNAME, TXT, Everything, keep 1 hour between the creation of new ones and still the same response
Status changed to Awaiting Railway Response Railway • about 1 month ago
a month ago
The underlying problem is still present: your DNS provider (Cloudflare) is still serving two stale ACME challenge TXT values from earlier issuance attempts, even after you deleted and recreated the record. Deleting the CNAME does not clear Cloudflare's internal cache of the flattened TXT values it previously resolved, so the certificate authority keeps reading tokens we never published and rejects the challenge. You will need to contact Cloudflare support and ask them to purge the cached TXT records at the ACME challenge subdomain for your zone, since that cache is on their side and not something you or we can clear through DNS record changes alone.
Status changed to Awaiting User Response Railway • about 1 month ago
a month ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • about 1 month ago