Failed to issue TLS certificate for wildcard domain (internal error)
rodrigossb
PROOP

12 days ago

Hi,

I'm hitting a persistent failure issuing the TLS certificate for a wildcard custom domain, and the dashboard only returns a generic error.

Error shown: "Failed to issue TLS certificate — An internal error occurred. Please retry or contact support."

What I've already verified (DNS is correct):

DNS is managed on Cloudflare, with the records set to DNS only (proxy disabled / grey cloud).

Wildcard: *.dyflow.com.br → CNAME → p5yt7eo3.up.railway.app (resolving correctly).

ACME challenge: _acme-challenge.dyflow.com.br → CNAME → p5yt7eo3.authorize.railwaydns.net. The token matches the wildcard's target.

No CAA records on the domain (any CA is allowed to issue).

I've waited over an hour and clicked "Try Again" several times, always getting the same internal error.

The domain already routes correctly (traffic reaches the service); the only problem is the wildcard certificate issuance. Could you check the issuance logs on your side and tell me the actual reason for the failure (Let's Encrypt rate limit, internal error, etc.)?

Thanks.

Solved

1 Replies

Railway
BOT

12 days ago

Cloudflare's authoritative nameservers are serving conflicting certificate challenge values, and Cloudflare needs to resolve that DNS conflict. Your _acme-challenge CNAME is correct and points at our delegation target, but when the certificate authority asks Cloudflare's nameservers directly for the TXT record, they answer with a value that is not one of the tokens we publish, so the DNS-01 validation cannot succeed. A normal public lookup that follows the CNAME can still show our token, which is why your checks looked clean.

Cloudflare can create its own _acme-challenge TXT records for its edge certificates, including leftovers from earlier certificate orders, and these do not always appear in the dashboard's record list or a zone export. Recreating the CNAME will not clear them. Querying one of your Cloudflare nameservers with +norecurse for the TXT record on your _acme-challenge name shows the conflicting value, and that result is what to take to Cloudflare so they can find and remove it.

Once Cloudflare's nameservers stop returning that value, use "Try Again" on the domain in the service's networking settings to start a fresh certificate order, since the failed attempts cannot turn valid on their own.


Status changed to Awaiting User Response Railway • 12 days ago


Railway
BOT

5 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 5 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...