23 days ago
I'm trying to add the wildcard domain *.delyes.com to my web service, but certificate issuance is stuck at "Certificate Authority is validating challenges" and fails with a TLS error.
Project Details:
Project ID: 557e6581-e30a-4a19-80f8-1fcd3b1bc31d
Environment: dev
Service: @delyes/web (cf6179cc-f4ab-4549-bd61-ade9fb57325d)
Domain: *.delyes.com
DNS Configuration (all verified and current):
delyes.com TXT record: railway-verify=613e9ba875601e0e5c9e095a2b0878f67e5869d369f8df9053a2dc828fe284c1 (resolving correctly)
_acme-challenge.delyes.com CNAME: pointing to Railway's current challenge server (correct target, newly generated for wildcard)
*.delyes.com CNAME: pointing to web service Railway domain (correct target)
All records set to DNS-only in Cloudflare
CAA record configured: 0 issuewild "letsencrypt.org"
What I've done:
Successfully added delyes.com (base domain) to @delyes/web service — certificate issued fine ✅
Attempted to add *.delyes.com (wildcard) to the same service
Railway requested _acme-challenge.delyes.com CNAME record (first request for wildcard, not reusing base domain ACME record)
Configured the ACME CNAME with Railway's provided target value
Waited for DNS propagation (5-10 minutes)
Clicked Retry multiple times in Railway
Certificate issuance stuck at "Certificate Authority is validating challenges" → TLS error
Verified all DNS records are current and resolving correctly
Confirmed all CNAME targets match exactly what Railway is asking for
Current State:
Base domain (delyes.com) certificate works fine
Wildcard (*.delyes.com) certificate issuance consistently fails at ACME validation stage
All DNS records are correct and current
No DNS configuration errors detected
This appears to be a bug in Railway's wildcard certificate provisioning with Let's Encrypt ACME validation.
1 Replies
23 days ago
Your DNS provider's authoritative nameservers are serving cached ACME challenge values that no longer match what we published at the delegation target, so the certificate authority rejects every validation attempt. This is a known behavior with providers that flatten the CNAME and cache their own copy of the TXT records. To fix it, delete the _acme-challenge CNAME record at your DNS provider, wait a moment, then recreate it using the value shown in the domain's settings in your Railway dashboard. If your provider keeps serving the old values after that, ask them to flush their cache for that record.
Status changed to Awaiting User Response Railway • 23 days ago
15 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 15 days ago