SSL cert issued but not propagating to EU Fastly edge POPs
ayushkumarcode
FREEOP

2 months ago

Project: hearty-compassion (1ac26511-0e8c-49a4-9549-d6ab68ee84b3)

Service: hearty-compassion (b0e5a913-1582-4e1b-aa63-065595ae53f3)

Domain: thursday.bot

Region: europe-west4-drams3a

DNS is fully verified (both green checkmarks in dashboard). SSL cert was issued at 09:55 UTC today (Let's Encrypt R13, expires 2026-06-24). The cert works from US locations (verified via ssl-checker.io), but the London Fastly POP (cache-lcy-egml8630077-LCY) returns "no peer certificate available" -TLS handshake gets connection reset. It's been 4.5+ hours.

The *.up.railway.app service domain works fine. Only the custom domain cert is affected on EU edges.

Solved

1 Replies

Railway
BOT

2 months ago

Our internal status shows your certificate for thursday.bot is valid and complete, and DNS is marked as propagated. However, public DNS resolves thursday.bot to an A record (151.101.2.15) rather than a CNAME pointing to o5vetmp0.up.railway.app, which is the expected CNAME target. This A record appears to belong to a different service and would prevent our edge from serving the correct certificate. You'll need to update your DNS at Porkbun to replace the A record with a CNAME record pointing to o5vetmp0.up.railway.app for the certificate to be served correctly across all edge locations.


Status changed to Awaiting User Response Railway about 2 months ago


Railway
BOT

2 months ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway about 2 months ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...