Wildcard cert repeatedly fails with "An internal error occurred"
tmvst
HOBBYOP

a month ago

My wildcard custom domain has been unable to get a TLS certificate for ~3 days. The status API reports CERTIFICATE_STATUS_TYPE_ISSUE_FAILED with errorMessage: "An internal error occurred. Please retry or contact support." and retryable: true. Pressing "Try Again" fails again after a while with the same error.

IDs:

  • Project: 52d4696d-c78b-45ce-a7b4-da3beebcf8af
  • Service: server (e9c5ce81-342f-4a8d-93ea-f182908ab360)
  • Environment: production (91a06f64-fe97-4035-926a-fd93bc231b1d)
  • Domain: *.thirdpass.app (8e2c958b-1905-4bcd-8b4b-eddb6ae8e649), target port 8787

What I've already ruled out:

  • DNS is correct and propagated (dashboard shows both records green, domain verified: true). DNS is on Cloudflare, all relevant records DNS-only (grey cloud).
  • _acme-challenge.thirdpass.app → CNAME → 6ibgnwns.authorize.railwaydns.net, resolves publicly and currently serves a challenge token TXT.
  • *.thirdpass.app → CNAME → 6ibgnwns.up.railway.app, propagated.
  • No CAA records on the domain, no DNSSEC (no DS record).
  • I deleted and re-added the domain once (previous domain ID 90795c22-9fb4-4033-b879-9a3938047ff0, old target 1tyvv7iz.*) and updated DNS to the new targets, same failure.
  • crt.sh shows no issuance attempts for *.thirdpass.app at all (only successful certs for platform.thirdpass.app, a non-wildcard domain on the same service, which works fine) so it doesn't look like a Let's Encrypt validation failure or rate limit. The order appears to fail inside Railway before reaching the CA.

Could you take a look at what the internal error is on the issuer side? Happy to provide anything else. Thanks!

Solved

5 Replies

Status changed to Awaiting Railway Response Railway • about 1 month ago


lineup-events
HOBBY

a month ago

Hey, your cert config seems to be misconfigured.

CN is *.up.railway.app not

*.thirdpass.app

image.png

Attachments


Status changed to Awaiting Railway Response Railway • about 1 month ago


Status changed to Awaiting User Response Railway • about 1 month ago


lineup-events
HOBBY

a month ago

That's probably why you don't see any attempts for *.thirdpass.app by crt.sh


Status changed to Awaiting Railway Response Railway • about 1 month ago


Status changed to Awaiting User Response Railway • about 1 month ago


tmvst
HOBBYOP

a month ago

The *.up.railway.app CN is the symptom, not the cause. That's Railway's fallback cert, served because the certificate for *.thirdpass.app has never been issued. Certificates are Railway-managed, there's no cert configuration on my side to fix.

The dashboard/API show the domain as verified with both DNS records propagated, but the certificate status is CERTIFICATE_STATUS_TYPE_ISSUE_FAILED with errorMessage: "An internal error occurred. Please retry or contact support." and clicking "Try Again" just reproduces it. The _acme-challenge.thirdpass.app CNAME delegation to 6ibgnwns.authorize.railwaydns.net resolves publicly and serves a live token, there are no CAA/DNSSEC records, and CT logs show no issuance attempt for *.thirdpass.app ever reached Let's Encrypt.


Status changed to Awaiting Railway Response Railway • about 1 month ago


tmvst
HOBBYOP

a month ago

Could someone from Railway please look at what the internal error is in your issuance pipeline for domain ID 8e2c958b-1905-4bcd-8b4b-eddb6ae8e649?


Status changed to Awaiting Railway Response Railway • about 1 month ago


sam-a
EMPLOYEE

a month ago

Your DNS configuration is correct and the ACME challenge delegation is healthy. The certificate issuance for this domain was failing inside our pipeline. We've re-triggered issuance, which may take a few minutes to complete.


Status changed to Awaiting User Response Railway • about 1 month ago


Status changed to Solved tmvst • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...