2 months ago
Hi Railway team,
I'm seeing wildcard TLS certificate issuance get stuck on two custom domains in the same project (resilient-compassion), on two different services. Reporting both together in case it's related.
- *.wamarcket.com — confirmed internal error, needs server-side investigation
Service: wm-frontend, environment: staging
Domain ID: 44969777-c814-4b6d-ae00-def078e3d2fa
Certificate has failed 4 times in a row with: "An internal error occurred. Please retry or contact support." (CERTIFICATE_ERROR_TYPE_INTERNAL, retryable: true)
Cycles ISSUE_FAILED → ISSUING → ISSUE_FAILED, never reaches VALID
DNS confirmed correctly propagated (verified via dig against multiple resolvers, both records match Railway's expected targets):
CNAME * → xeezrij1.up.railway.app (PROPAGATED)
CNAME _acme-challenge → xeezrij1.authorize.railwaydns.net (PROPAGATED)
The non-wildcard apex wamarcket.com on the same service issued its certificate successfully on the first try — this looks specific to wildcard issuance.
Already reported separately at station.railway.com (thread: "Wildcard SSL certificate stuck in ISSUE_FAILED — *.wamarcket.com"), still awaiting response.
- *.getguestconnect.com — DNS was missing, now added, currently pending
Service: gc-frontend, environment: production
Domain ID: 0351fc66-9f87-425e-9529-99637b528b4f
Both required CNAME records were missing entirely (likely proxied through Cloudflare instead of DNS-only). Corrected and confirmed propagated via dig (Google + Cloudflare resolvers) as of [heure].
Certificate currently shows VALIDATING_OWNERSHIP — not failed, just monitoring to confirm it reaches VALID on its own now that DNS is correct.
Flagging here only in case it also stalls with the same internal error once DNS validation completes — will update this thread either way.
Could you check server-side, particularly for domain 1, whether an ACME order was submitted, what the DNS-01 challenge returned, and whether there's an internal error or rate limit blocking issuance?
Thanks!
11 Replies
Status changed to Awaiting Railway Response Railway • about 2 months ago
2 months ago
Your DNS is configured correctly and the domain is verified. The certificate issuance pipeline for *.wamarcket.com appears stuck in a loop, so we've re-triggered it. This may take a few minutes to complete. If it doesn't resolve within an hour or so, reply here and we'll dig deeper.
Status changed to Awaiting User Response Railway • about 2 months ago
Status changed to Awaiting Railway Response Railway • about 2 months ago
2 months ago
Hi, following up — it's been well over an hour since the re-trigger and the certificate is still stuck in the same state:
Certificate status: ISSUE_FAILED (unchanged)
Certificate error: "An internal error occurred. Please retry or contact support." (CERTIFICATE_ERROR_TYPE_INTERNAL, retryable: true)
DNS records unchanged, still fully propagated:
CNAME * -> xeezrij1.up.railway.app
CNAME _acme-challenge -> xeezrij1.authorize.railwaydns.net
As you mentioned this might need deeper investigation if it didn't resolve within an hour — could you take another look? Happy to provide any additional info needed.
Thanks!
2 months ago
Your DNS is confirmed correct on both records, and the domain is verified. The certificate issuance pipeline for *.wamarcket.com has been re-triggered through a different path. This should complete within a few minutes. If the certificate still shows ISSUE_FAILED after that, reply here and we will investigate the ACME challenge infrastructure for this domain directly.
Status changed to Awaiting User Response Railway • about 2 months ago
2 months ago
The certificate still displays the status ISSUE_FAILED
Status changed to Awaiting Railway Response Railway • about 2 months ago
wilzuck
The certificate still displays the status ISSUE_FAILED
2 months ago
Attachments
2 months ago
Your DNS is confirmed correct on both records, and this failure is on our certificate issuance pipeline, not anything on your side. We've re-triggered certificate issuance for *.wamarcket.com through a different path. It may take a few minutes to complete.
Status changed to Awaiting User Response Railway • about 2 months ago
2 months ago
Help me please !
ISSUE_FAILED / CERTIFICATE_ERROR_TYPE_INTERNAL
Status changed to Awaiting Railway Response Railway • about 2 months ago
2 months ago
To correct an earlier assessment, this certificate failure is caused by your DNS provider (Cloudflare), not by our issuance pipeline. Cloudflare's authoritative nameservers are serving stale ACME challenge TXT values that we never published, so the certificate authority rejects every attempt. Your CNAME delegation record itself is correct (which is why dig looks fine), but Cloudflare is flattening it and caching outdated values instead of letting resolvers follow the CNAME. To fix this, delete the _acme-challenge.wamarcket.com CNAME record in Cloudflare, wait a minute, then recreate it using the value shown in your Railway dashboard for *.wamarcket.com, and make sure it is set to DNS-only (grey cloud). Once Cloudflare stops serving the stale values, certificate issuance should complete on its own.
Status changed to Awaiting User Response Railway • about 2 months ago
Status changed to Awaiting Railway Response Railway • about 2 months ago
2 months ago
The same root cause persists: your DNS provider's authoritative nameservers are still serving stale ACME challenge TXT values that we never published, so every issuance attempt fails identically. Since deleting and recreating the record did not clear the cached values, the next step is to contact Cloudflare support and ask them to purge the stale TXT records on the ACME challenge subdomain for your wildcard domain. Once those stale values are gone, certificate issuance should complete on its own.
Status changed to Awaiting User Response Railway • about 2 months ago
a month ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • about 1 month ago