Wildcard certificate repeatedly fails after verified DNS
brudolf
HOBBYOP

2 hours ago

Our Design platform's apex getdesign.hu serves trusted HTTPS, but the certificate

for *.getdesign.hu has repeatedly failed with an internal Railway error. This

blocks administration and customer workspace HTTPS. The shared ingress service

is healthy; all workspace traffic is intended to use shared application services.

This is a certificate issuance problem, before application HTTP routing.

Awaiting User Response

1 Replies

Railway
BOT

2 hours ago

Your _acme-challenge CNAME points at the correct target, but Cloudflare's authoritative nameservers are serving conflicting certificate challenge values. When asked for TXT records on that name, both nameservers return two TXT values that don't match any value currently published at our delegation target, so the certificate authority can't get the expected token and validation fails. The generic "internal error" message on the certificate doesn't change this.

Cloudflare needs to resolve that DNS conflict. These values don't show up as editable records in your zone, so they're likely TXT records that Cloudflare manages for its own edge certificates (Universal, Advanced or backup), which can stay hidden from the dashboard. You can see the mismatch by running a non-recursive TXT query for the challenge name against your Cloudflare nameservers and comparing the result with the TXT at the delegation target shown in your domain settings. Cloudflare support can then identify and remove the conflicting records.

Recreating the CNAME or retrying issuance won't help until Cloudflare stops serving those values. Once it does, the certificate needs a fresh issuance attempt, because the failed attempt can't succeed on its own.


Status changed to Awaiting User Response Railway • about 2 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...