Wildcard domain *.delyes.com certificate issuance stuck at ACME validation
lucasdelye
PROOP

23 days ago

I'm trying to add the wildcard domain *.delyes.com to my web service, but certificate issuance is stuck at "Certificate Authority is validating challenges" and fails with a TLS error.

Project Details:

Project ID: 557e6581-e30a-4a19-80f8-1fcd3b1bc31d

Environment: dev

Service: @delyes/web (cf6179cc-f4ab-4549-bd61-ade9fb57325d)

Domain: *.delyes.com

DNS Configuration (all verified and current):

delyes.com TXT record: railway-verify=613e9ba875601e0e5c9e095a2b0878f67e5869d369f8df9053a2dc828fe284c1 (resolving correctly)

_acme-challenge.delyes.com CNAME: pointing to Railway's current challenge server (correct target, newly generated for wildcard)

*.delyes.com CNAME: pointing to web service Railway domain (correct target)

All records set to DNS-only in Cloudflare

CAA record configured: 0 issuewild "letsencrypt.org"

What I've done:

Successfully added delyes.com (base domain) to @delyes/web service — certificate issued fine ✅

Attempted to add *.delyes.com (wildcard) to the same service

Railway requested _acme-challenge.delyes.com CNAME record (first request for wildcard, not reusing base domain ACME record)

Configured the ACME CNAME with Railway's provided target value

Waited for DNS propagation (5-10 minutes)

Clicked Retry multiple times in Railway

Certificate issuance stuck at "Certificate Authority is validating challenges" → TLS error

Verified all DNS records are current and resolving correctly

Confirmed all CNAME targets match exactly what Railway is asking for

Current State:

Base domain (delyes.com) certificate works fine

Wildcard (*.delyes.com) certificate issuance consistently fails at ACME validation stage

All DNS records are correct and current

No DNS configuration errors detected

This appears to be a bug in Railway's wildcard certificate provisioning with Let's Encrypt ACME validation.

Solved

1 Replies

Railway
BOT

23 days ago

Your DNS provider's authoritative nameservers are serving cached ACME challenge values that no longer match what we published at the delegation target, so the certificate authority rejects every validation attempt. This is a known behavior with providers that flatten the CNAME and cache their own copy of the TXT records. To fix it, delete the _acme-challenge CNAME record at your DNS provider, wait a moment, then recreate it using the value shown in the domain's settings in your Railway dashboard. If your provider keeps serving the old values after that, ask them to flush their cache for that record.


Status changed to Awaiting User Response Railway • 23 days ago


Railway
BOT

15 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 15 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...