a day ago
Hi Railway team,
I'm seeing wildcard TLS certificate issuance get stuck on two custom domains in the same project (resilient-compassion), on two different services. Reporting both together in case it's related.
- *.wamarcket.com — confirmed internal error, needs server-side investigation
Service: wm-frontend, environment: staging
Domain ID: 44969777-c814-4b6d-ae00-def078e3d2fa
Certificate has failed 4 times in a row with: "An internal error occurred. Please retry or contact support." (CERTIFICATE_ERROR_TYPE_INTERNAL, retryable: true)
Cycles ISSUE_FAILED → ISSUING → ISSUE_FAILED, never reaches VALID
DNS confirmed correctly propagated (verified via dig against multiple resolvers, both records match Railway's expected targets):
CNAME * → xeezrij1.up.railway.app (PROPAGATED)
CNAME _acme-challenge → xeezrij1.authorize.railwaydns.net (PROPAGATED)
The non-wildcard apex wamarcket.com on the same service issued its certificate successfully on the first try — this looks specific to wildcard issuance.
Already reported separately at station.railway.com (thread: "Wildcard SSL certificate stuck in ISSUE_FAILED — *.wamarcket.com"), still awaiting response.
- *.getguestconnect.com — DNS was missing, now added, currently pending
Service: gc-frontend, environment: production
Domain ID: 0351fc66-9f87-425e-9529-99637b528b4f
Both required CNAME records were missing entirely (likely proxied through Cloudflare instead of DNS-only). Corrected and confirmed propagated via dig (Google + Cloudflare resolvers) as of [heure].
Certificate currently shows VALIDATING_OWNERSHIP — not failed, just monitoring to confirm it reaches VALID on its own now that DNS is correct.
Flagging here only in case it also stalls with the same internal error once DNS validation completes — will update this thread either way.
Could you check server-side, particularly for domain 1, whether an ACME order was submitted, what the DNS-01 challenge returned, and whether there's an internal error or rate limit blocking issuance?
Thanks!
4 Replies
Status changed to Awaiting Railway Response Railway • about 23 hours ago
a day ago
Your DNS is configured correctly and the domain is verified. The certificate issuance pipeline for *.wamarcket.com appears stuck in a loop, so we've re-triggered it. This may take a few minutes to complete. If it doesn't resolve within an hour or so, reply here and we'll dig deeper.
Status changed to Awaiting User Response Railway • about 22 hours ago
Status changed to Awaiting Railway Response Railway • about 8 hours ago
8 hours ago
Hi, following up — it's been well over an hour since the re-trigger and the certificate is still stuck in the same state:
Certificate status: ISSUE_FAILED (unchanged)
Certificate error: "An internal error occurred. Please retry or contact support." (CERTIFICATE_ERROR_TYPE_INTERNAL, retryable: true)
DNS records unchanged, still fully propagated:
CNAME * -> xeezrij1.up.railway.app
CNAME _acme-challenge -> xeezrij1.authorize.railwaydns.net
As you mentioned this might need deeper investigation if it didn't resolve within an hour — could you take another look? Happy to provide any additional info needed.
Thanks!
4 hours ago
Your DNS is confirmed correct on both records, and the domain is verified. The certificate issuance pipeline for *.wamarcket.com has been re-triggered through a different path. This should complete within a few minutes. If the certificate still shows ISSUE_FAILED after that, reply here and we will investigate the ACME challenge infrastructure for this domain directly.
Status changed to Awaiting User Response Railway • about 4 hours ago