10 hours ago
I need you to purge the cached DNS TXT records for the ACME challenge
subdomain on my zone audigrowth.com.br.
The specific record is: _acme-challenge.audigrowth.com.br
I'm trying to issue a wildcard SSL certificate via Let's Encrypt through
Railway (my hosting provider). The certificate authority keeps reading
stale ACME challenge values that Cloudflare has cached from previous
issuance attempts, even after I deleted and recreated the DNS record
multiple times.
Railway support confirmed this is a Cloudflare internal cache issue.
Can you please purge the cached TXT values for that subdomain?
Zone: audigrowth.com.br
Record to purge: _acme-challenge.audigrowth.com.br
3 Replies
10 hours ago
Your wildcard certificate is stuck because your DNS provider's authoritative nameservers are serving cached ACME challenge TXT values from a previous issuance attempt, which don't match the current token we published. The delegation CNAME itself is correct, but the provider is flattening it and answering with stale data, so every issuance attempt fails identically. To fix this, delete the ACME challenge CNAME record at your DNS provider, wait a moment, then recreate it using the value shown in your service's Settings under Networking in the Railway dashboard. If your provider continues serving the old values after that, you'll need to ask their support to flush the cached records for that challenge subdomain.
Status changed to Awaiting User Response Railway • about 10 hours ago
9 hours ago
I have already tried deleting and recreating the _acme-challenge CNAME
record multiple times over several days. The issue persists.
Railway support in another thread confirmed this is a Cloudflare internal
cache problem — Cloudflare is flattening the CNAME and serving stale TXT
values even after the record is deleted and recreated.
I contacted Cloudflare support to purge the cached records for
_acme-challenge.audigrowth.com.br. While waiting for their response,
can a Railway staff member please force-issue the certificate manually
on your end, or confirm if there is a backend fix available?
This has been failing for over a week.
Status changed to Awaiting Railway Response Railway • about 9 hours ago
an hour ago
I have already tried deleting and recreating the _acme-challenge CNAME
multiple times over several days, including waiting hours between attempts.
The issue persists.
I found this thread where a Railway employee (brody) manually kicked off
a certificate re-issuance for a user with the same symptoms:
https://station.railway.com/questions/ssl-certificate-not-provisioning-for-cus-dfa2f3bd
My DNS configuration is correct (verified), no CAA records, Cloudflare
SSL/TLS in Full mode, Universal SSL active. This appears to be the same
internal Railway certificate issuance error.
Could a Railway staff member please manually kick off a certificate
re-issuance for *.audigrowth.com.br?
Project: grand-nourishment
Service: audi-growth
Environment: production
Domain: *.audigrowth.com.br
Status changed to Awaiting Railway Response Railway • about 1 hour ago