Subject: Wildcard certificate issuance stuck — two custom domains, same project
wilzuck
HOBBYOP

2 months ago

Hi Railway team,

I'm seeing wildcard TLS certificate issuance get stuck on two custom domains in the same project (resilient-compassion), on two different services. Reporting both together in case it's related.

  1. *.wamarcket.com — confirmed internal error, needs server-side investigation

Service: wm-frontend, environment: staging

Domain ID: 44969777-c814-4b6d-ae00-def078e3d2fa

Certificate has failed 4 times in a row with: "An internal error occurred. Please retry or contact support." (CERTIFICATE_ERROR_TYPE_INTERNAL, retryable: true)

Cycles ISSUE_FAILED → ISSUING → ISSUE_FAILED, never reaches VALID

DNS confirmed correctly propagated (verified via dig against multiple resolvers, both records match Railway's expected targets):

CNAME * → xeezrij1.up.railway.app (PROPAGATED)

CNAME _acme-challenge → xeezrij1.authorize.railwaydns.net (PROPAGATED)

The non-wildcard apex wamarcket.com on the same service issued its certificate successfully on the first try — this looks specific to wildcard issuance.

Already reported separately at station.railway.com (thread: "Wildcard SSL certificate stuck in ISSUE_FAILED — *.wamarcket.com"), still awaiting response.

  1. *.getguestconnect.com — DNS was missing, now added, currently pending

Service: gc-frontend, environment: production

Domain ID: 0351fc66-9f87-425e-9529-99637b528b4f

Both required CNAME records were missing entirely (likely proxied through Cloudflare instead of DNS-only). Corrected and confirmed propagated via dig (Google + Cloudflare resolvers) as of [heure].

Certificate currently shows VALIDATING_OWNERSHIP — not failed, just monitoring to confirm it reaches VALID on its own now that DNS is correct.

Flagging here only in case it also stalls with the same internal error once DNS validation completes — will update this thread either way.

Could you check server-side, particularly for domain 1, whether an ACME order was submitted, what the DNS-01 challenge returned, and whether there's an internal error or rate limit blocking issuance?

Thanks!

Solved

11 Replies

Status changed to Awaiting Railway Response Railway • about 2 months ago


2 months ago

Your DNS is configured correctly and the domain is verified. The certificate issuance pipeline for *.wamarcket.com appears stuck in a loop, so we've re-triggered it. This may take a few minutes to complete. If it doesn't resolve within an hour or so, reply here and we'll dig deeper.


Status changed to Awaiting User Response Railway • about 2 months ago


wilzuck
HOBBYOP

2 months ago

Capture d’écran 2026-08-16 à 18.41.43.png

Attachments


Status changed to Awaiting Railway Response Railway • about 2 months ago


wilzuck
HOBBYOP

2 months ago

Hi, following up — it's been well over an hour since the re-trigger and the certificate is still stuck in the same state:

Certificate status: ISSUE_FAILED (unchanged)

Certificate error: "An internal error occurred. Please retry or contact support." (CERTIFICATE_ERROR_TYPE_INTERNAL, retryable: true)

DNS records unchanged, still fully propagated:

CNAME * -> xeezrij1.up.railway.app

CNAME _acme-challenge -> xeezrij1.authorize.railwaydns.net

As you mentioned this might need deeper investigation if it didn't resolve within an hour — could you take another look? Happy to provide any additional info needed.

Thanks!


2 months ago

Your DNS is confirmed correct on both records, and the domain is verified. The certificate issuance pipeline for *.wamarcket.com has been re-triggered through a different path. This should complete within a few minutes. If the certificate still shows ISSUE_FAILED after that, reply here and we will investigate the ACME challenge infrastructure for this domain directly.


Status changed to Awaiting User Response Railway • about 2 months ago


wilzuck
HOBBYOP

2 months ago

The certificate still displays the status ISSUE_FAILED


Status changed to Awaiting Railway Response Railway • about 2 months ago


wilzuck

The certificate still displays the status ISSUE_FAILED

wilzuck
HOBBYOP

2 months ago

Capture d’écran 2026-08-17 à 12.41.21.png

Attachments


2 months ago

Your DNS is confirmed correct on both records, and this failure is on our certificate issuance pipeline, not anything on your side. We've re-triggered certificate issuance for *.wamarcket.com through a different path. It may take a few minutes to complete.


Status changed to Awaiting User Response Railway • about 2 months ago


wilzuck
HOBBYOP

2 months ago

Help me please !

ISSUE_FAILED / CERTIFICATE_ERROR_TYPE_INTERNAL


Status changed to Awaiting Railway Response Railway • about 2 months ago


Railway
BOT

2 months ago

To correct an earlier assessment, this certificate failure is caused by your DNS provider (Cloudflare), not by our issuance pipeline. Cloudflare's authoritative nameservers are serving stale ACME challenge TXT values that we never published, so the certificate authority rejects every attempt. Your CNAME delegation record itself is correct (which is why dig looks fine), but Cloudflare is flattening it and caching outdated values instead of letting resolvers follow the CNAME. To fix this, delete the _acme-challenge.wamarcket.com CNAME record in Cloudflare, wait a minute, then recreate it using the value shown in your Railway dashboard for *.wamarcket.com, and make sure it is set to DNS-only (grey cloud). Once Cloudflare stops serving the stale values, certificate issuance should complete on its own.


Status changed to Awaiting User Response Railway • about 2 months ago


wilzuck
HOBBYOP

2 months ago

Same thing

Capture d’écran 2026-08-21 à 01.03.29.png

Attachments


Status changed to Awaiting Railway Response Railway • about 2 months ago


Railway
BOT

2 months ago

The same root cause persists: your DNS provider's authoritative nameservers are still serving stale ACME challenge TXT values that we never published, so every issuance attempt fails identically. Since deleting and recreating the record did not clear the cached values, the next step is to contact Cloudflare support and ask them to purge the stale TXT records on the ACME challenge subdomain for your wildcard domain. Once those stale values are gone, certificate issuance should complete on its own.


Status changed to Awaiting User Response Railway • about 2 months ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...