Subject: Wildcard certificate issuance stuck — two custom domains, same project
wilzuck
HOBBYOP

a day ago

Hi Railway team,

I'm seeing wildcard TLS certificate issuance get stuck on two custom domains in the same project (resilient-compassion), on two different services. Reporting both together in case it's related.

  1. *.wamarcket.com — confirmed internal error, needs server-side investigation

Service: wm-frontend, environment: staging

Domain ID: 44969777-c814-4b6d-ae00-def078e3d2fa

Certificate has failed 4 times in a row with: "An internal error occurred. Please retry or contact support." (CERTIFICATE_ERROR_TYPE_INTERNAL, retryable: true)

Cycles ISSUE_FAILED → ISSUING → ISSUE_FAILED, never reaches VALID

DNS confirmed correctly propagated (verified via dig against multiple resolvers, both records match Railway's expected targets):

CNAME * → xeezrij1.up.railway.app (PROPAGATED)

CNAME _acme-challenge → xeezrij1.authorize.railwaydns.net (PROPAGATED)

The non-wildcard apex wamarcket.com on the same service issued its certificate successfully on the first try — this looks specific to wildcard issuance.

Already reported separately at station.railway.com (thread: "Wildcard SSL certificate stuck in ISSUE_FAILED — *.wamarcket.com"), still awaiting response.

  1. *.getguestconnect.com — DNS was missing, now added, currently pending

Service: gc-frontend, environment: production

Domain ID: 0351fc66-9f87-425e-9529-99637b528b4f

Both required CNAME records were missing entirely (likely proxied through Cloudflare instead of DNS-only). Corrected and confirmed propagated via dig (Google + Cloudflare resolvers) as of [heure].

Certificate currently shows VALIDATING_OWNERSHIP — not failed, just monitoring to confirm it reaches VALID on its own now that DNS is correct.

Flagging here only in case it also stalls with the same internal error once DNS validation completes — will update this thread either way.

Could you check server-side, particularly for domain 1, whether an ACME order was submitted, what the DNS-01 challenge returned, and whether there's an internal error or rate limit blocking issuance?

Thanks!

Awaiting User Response

4 Replies

Status changed to Awaiting Railway Response Railway about 23 hours ago


a day ago

Your DNS is configured correctly and the domain is verified. The certificate issuance pipeline for *.wamarcket.com appears stuck in a loop, so we've re-triggered it. This may take a few minutes to complete. If it doesn't resolve within an hour or so, reply here and we'll dig deeper.


Status changed to Awaiting User Response Railway about 22 hours ago


wilzuck
HOBBYOP

8 hours ago

Capture d’écran 2026-08-16 à 18.41.43.png

Attachments


Status changed to Awaiting Railway Response Railway about 8 hours ago


wilzuck
HOBBYOP

8 hours ago

Hi, following up — it's been well over an hour since the re-trigger and the certificate is still stuck in the same state:

Certificate status: ISSUE_FAILED (unchanged)

Certificate error: "An internal error occurred. Please retry or contact support." (CERTIFICATE_ERROR_TYPE_INTERNAL, retryable: true)

DNS records unchanged, still fully propagated:

CNAME * -> xeezrij1.up.railway.app

CNAME _acme-challenge -> xeezrij1.authorize.railwaydns.net

As you mentioned this might need deeper investigation if it didn't resolve within an hour — could you take another look? Happy to provide any additional info needed.

Thanks!


4 hours ago

Your DNS is confirmed correct on both records, and the domain is verified. The certificate issuance pipeline for *.wamarcket.com has been re-triggered through a different path. This should complete within a few minutes. If the certificate still shows ISSUE_FAILED after that, reply here and we will investigate the ACME challenge infrastructure for this domain directly.


Status changed to Awaiting User Response Railway about 4 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...