a month ago
My wildcard custom domain has been unable to get a TLS certificate for ~3 days. The status API reports CERTIFICATE_STATUS_TYPE_ISSUE_FAILED with errorMessage: "An internal error occurred. Please retry or contact support." and retryable: true. Pressing "Try Again" fails again after a while with the same error.
IDs:
- Project:
52d4696d-c78b-45ce-a7b4-da3beebcf8af - Service:
server(e9c5ce81-342f-4a8d-93ea-f182908ab360) - Environment:
production(91a06f64-fe97-4035-926a-fd93bc231b1d) - Domain:
*.thirdpass.app(8e2c958b-1905-4bcd-8b4b-eddb6ae8e649), target port 8787
What I've already ruled out:
- DNS is correct and propagated (dashboard shows both records green, domain
verified: true). DNS is on Cloudflare, all relevant records DNS-only (grey cloud). _acme-challenge.thirdpass.app→ CNAME →6ibgnwns.authorize.railwaydns.net, resolves publicly and currently serves a challenge token TXT.*.thirdpass.app→ CNAME →6ibgnwns.up.railway.app, propagated.- No CAA records on the domain, no DNSSEC (no DS record).
- I deleted and re-added the domain once (previous domain ID
90795c22-9fb4-4033-b879-9a3938047ff0, old target1tyvv7iz.*) and updated DNS to the new targets, same failure. - crt.sh shows no issuance attempts for
*.thirdpass.appat all (only successful certs forplatform.thirdpass.app, a non-wildcard domain on the same service, which works fine) so it doesn't look like a Let's Encrypt validation failure or rate limit. The order appears to fail inside Railway before reaching the CA.
Could you take a look at what the internal error is on the issuer side? Happy to provide anything else. Thanks!
5 Replies
Status changed to Awaiting Railway Response Railway • about 1 month ago
a month ago
Hey, your cert config seems to be misconfigured.
CN is *.up.railway.app not
*.thirdpass.app
Attachments
Status changed to Awaiting Railway Response Railway • about 1 month ago
Status changed to Awaiting User Response Railway • about 1 month ago
a month ago
That's probably why you don't see any attempts for *.thirdpass.app by crt.sh
Status changed to Awaiting Railway Response Railway • about 1 month ago
Status changed to Awaiting User Response Railway • about 1 month ago
a month ago
The *.up.railway.app CN is the symptom, not the cause. That's Railway's fallback cert, served because the certificate for *.thirdpass.app has never been issued. Certificates are Railway-managed, there's no cert configuration on my side to fix.
The dashboard/API show the domain as verified with both DNS records propagated, but the certificate status is CERTIFICATE_STATUS_TYPE_ISSUE_FAILED with errorMessage: "An internal error occurred. Please retry or contact support." and clicking "Try Again" just reproduces it. The _acme-challenge.thirdpass.app CNAME delegation to 6ibgnwns.authorize.railwaydns.net resolves publicly and serves a live token, there are no CAA/DNSSEC records, and CT logs show no issuance attempt for *.thirdpass.app ever reached Let's Encrypt.
Status changed to Awaiting Railway Response Railway • about 1 month ago
a month ago
Could someone from Railway please look at what the internal error is in your issuance pipeline for domain ID 8e2c958b-1905-4bcd-8b4b-eddb6ae8e649?
Status changed to Awaiting Railway Response Railway • about 1 month ago
a month ago
Your DNS configuration is correct and the ACME challenge delegation is healthy. The certificate issuance for this domain was failing inside our pipeline. We've re-triggered issuance, which may take a few minutes to complete.
Status changed to Awaiting User Response Railway • about 1 month ago
Status changed to Solved tmvst • about 1 month ago
