SSL/TLS Handshake Failure (Cloudflare wildcard domains)
seemusdesignandweb
PROOP

24 days ago

I am having issues here, (same as: https://station.railway.com/questions/persistent-error-525-with-cloudflare-wil-e544f733) with cloudflare and wildcard domains on railway. the only response to this on Railway help says to contact cloudflare, the link below asks things of railway.

https://community.cloudflare.com/t/stale-txt-records/802332/2

"Ask Railway to supply the content they require, for the TXT record, and add and/or update it regularly, when they need to issue a new certificate."

Was there any way of resolving this?

Solved

3 Replies

sam-a
EMPLOYEE

24 days ago

For wildcard domains, we handle the TXT record management automatically - you add a CNAME for _acme-challenge pointing to authorize.railwaydns.net, and we manage the actual TXT records on our end for certificate validation. The most common cause of Error 525 with Cloudflare wildcards is the _acme-challenge CNAME being proxied (orange cloud) when it must be DNS-only (grey cloud). Can you confirm the _acme-challenge record is set to grey cloud, Universal SSL is enabled, and SSL/TLS mode is set to Full (not Full Strict)?


Status changed to Awaiting User Response Railway 24 days ago


seemusdesignandweb
PROOP

24 days ago

Cloudflare was set as grey cloud, FULL (not Full Strict), Universal SSL is enabled. I updated the CNAME to [authorize.railwaydns.net](authorize.railwaydns.net)
but that didnt work, reverted it back to what Railway settings said, and it did work. So im not sure what the learning point there was. But happy its working.


Status changed to Awaiting Railway Response Railway 24 days ago


sam-a
EMPLOYEE

23 days ago

Apologies for previously sending generic values. Glad you got it working. Certificate issuance can sometimes just need time to propagate (typically up to an hour, occasionally longer).

Sorry this took longer than it should of. Let us know if you need further help.


Status changed to Awaiting User Response Railway 23 days ago


Railway
BOT

16 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway 16 days ago


Loading...