SSL Handshake Failed
plinpod
PROOP

3 months ago

Getting this all of a sudden for a sub domain.

Service ID: e64f9d88-c3f6-4ad8-b7bf-32d7cd8bdebd

image.png

Attachments

$20 Bounty

13 Replies

kokholm
PRO

3 months ago

Happens for us as well, as this looks like another Railway <> Cloudflare issue, and they always want multiple tickets. Here it is.

https://station.railway.com/questions/error-code-525-ssl-handshake-failed-fo-40af47ce


3 months ago

What domain?


plinpod
PROOP

3 months ago

There is multiple

e64f9d88-c3f6-4ad8-b7bf-32d7cd8bdebd

f834b589-619a-4dc0-be5f-9d97526f4aba


Railway
BOT

3 months ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway 3 months ago


3 months ago

It's related to a Cloudflare issue: https://new.cloudflarestatus.com/incidents/j17t8xz91xs0

Please disable Cloudflare's proxy (orange -> grey cloud) to resolve this.


plinpod
PROOP

3 months ago

This for certain on the cloudflare side? Their incident is 16 hours old my domains just went down a little while ago.


3 months ago

Hmm could you link me to your deployment?




3 months ago

Yeah I see, we also do not have TLS certificates on our side - usually caused by Cloudflare blocking access to our /.well-known ACME challenge path. This causes Cloudflare to fall back to loose/unmatched TLS to the origin (Railway), which has only broken now due to the incident. If you disable Cloudflare, you can delete+re-add the domain to Railway and we will immediately issue a new, valid TLS certificate for your service.


plinpod
PROOP

3 months ago

I deleted the domain in the railway service and re-added it. Updated the Cloudflare with the new DNS but it still is not working.


3 months ago

Which domain did you do this for? I still see the Cloudflare proxy activated.


plinpod
PROOP

3 months ago

Got it working now. I re-added the domains a second time and they are connecting now.

I think the first time I didn't delete the CNAME record on the Cloudflare side I just changed it's value. Deleting it completely and adding a new one looks like it did the trick


3 months ago

Good to hear, sorry you ran into this. If possible, I'd suggest either keeping domains pointing directly at Railway, and if not then ensure that your website is reachable at the /.well-known/acme-challenge/verify path so that our certificate renewal flow can run.


Status changed to Solved noahd 3 months ago


Status changed to Awaiting Conductor Response Railway 3 months ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...