Wildcard domain *.audigrowth.com.br failing to issue TLS certificate — internal error
growthaudi-cell
HOBBYOP

10 hours ago

I need you to purge the cached DNS TXT records for the ACME challenge

subdomain on my zone audigrowth.com.br.

The specific record is: _acme-challenge.audigrowth.com.br

I'm trying to issue a wildcard SSL certificate via Let's Encrypt through

Railway (my hosting provider). The certificate authority keeps reading

stale ACME challenge values that Cloudflare has cached from previous

issuance attempts, even after I deleted and recreated the DNS record

multiple times.

Railway support confirmed this is a Cloudflare internal cache issue.

Can you please purge the cached TXT values for that subdomain?

Zone: audigrowth.com.br

Record to purge: _acme-challenge.audigrowth.com.br

Awaiting Railway Response

3 Replies

Railway
BOT

10 hours ago

Your wildcard certificate is stuck because your DNS provider's authoritative nameservers are serving cached ACME challenge TXT values from a previous issuance attempt, which don't match the current token we published. The delegation CNAME itself is correct, but the provider is flattening it and answering with stale data, so every issuance attempt fails identically. To fix this, delete the ACME challenge CNAME record at your DNS provider, wait a moment, then recreate it using the value shown in your service's Settings under Networking in the Railway dashboard. If your provider continues serving the old values after that, you'll need to ask their support to flush the cached records for that challenge subdomain.


Status changed to Awaiting User Response Railway about 10 hours ago


growthaudi-cell
HOBBYOP

9 hours ago

I have already tried deleting and recreating the _acme-challenge CNAME

record multiple times over several days. The issue persists.

Railway support in another thread confirmed this is a Cloudflare internal

cache problem — Cloudflare is flattening the CNAME and serving stale TXT

values even after the record is deleted and recreated.

I contacted Cloudflare support to purge the cached records for

_acme-challenge.audigrowth.com.br. While waiting for their response,

can a Railway staff member please force-issue the certificate manually

on your end, or confirm if there is a backend fix available?

This has been failing for over a week.


Status changed to Awaiting Railway Response Railway about 9 hours ago


growthaudi-cell
HOBBYOP

an hour ago

I have already tried deleting and recreating the _acme-challenge CNAME

multiple times over several days, including waiting hours between attempts.

The issue persists.

I found this thread where a Railway employee (brody) manually kicked off

a certificate re-issuance for a user with the same symptoms:

https://station.railway.com/questions/ssl-certificate-not-provisioning-for-cus-dfa2f3bd

My DNS configuration is correct (verified), no CAA records, Cloudflare

SSL/TLS in Full mode, Universal SSL active. This appears to be the same

internal Railway certificate issuance error.

Could a Railway staff member please manually kick off a certificate

re-issuance for *.audigrowth.com.br?

Project: grand-nourishment

Service: audi-growth

Environment: production

Domain: *.audigrowth.com.br


Status changed to Awaiting Railway Response Railway about 1 hour ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...