GitHub Pages: HTTPS provisioning stuck on InvalidDNSError for custom domain dvs-servis75.ru #209216
Replies: 5 comments
|
Your apex A records are the standard GitHub Pages addresses:
The I would verify the DNS from multiple resolvers, especially checking for unexpected dig dvs-servis75.ru A +short
dig dvs-servis75.ru AAAA +short
dig www.dvs-servis75.ru CNAME +shortAlso check that there is no wildcard DNS record such as If those results are clean, try this once:
GitHub normally requests the Let's Encrypt certificate automatically once its DNS check succeeds, so a staff member generally shouldn't need to manually issue the certificate. If it remains on If this answer was helpful, please mark it as answered. |
|
The I’d check these things first:
If all of that is correct and it has been stuck for several days, it is likely something GitHub needs to investigate on their side. At that point, opening a GitHub Support ticket with the repository and domain information is the right next step. |
|
Execute a delayed hard reset: Removing and immediately re-adding the custom domain often fails because GitHub's backend caches the previous error state. Remove the custom domain from your repository settings entirely, wait at least 45 to 60 minutes to ensure the cache clears, and then add it back. Add an explicit CAA record: You noted that you do not have CAA records blocking Let's Encrypt. However, explicitly adding one can sometimes force the validation to succeed, especially with certain registrars like reg.ru that might have unique default behaviors. Add a CAA record for dvs-servis75.ru with the value 0 issue "letsencrypt.org". Verify DNSSEC configuration: Check your reg.ru control panel to ensure DNSSEC is either fully disabled or perfectly configured. A broken DNSSEC chain will cause Let's Encrypt's DNS lookups to fail, resulting in a persistent InvalidDNSError on GitHub's end even if standard HTTP traffic resolves correctly. Submit a specialized support ticket: To get a human GitHub staff member to manually intervene, you must submit a ticket through the GitHub Support portal. Go to support.github.com/contact/pages (or the general contact form if that direct link redirects) and select "Pages" as the category. Explicitly state that your DNS is fully propagated, you are stuck in an InvalidDNSError loop, and you need staff to manually clear the certificate state and trigger a re-issuance. |
|
Execute a delayed hard reset: Removing and immediately re-adding the custom domain often fails because GitHub's backend caches the previous error state. Remove the custom domain from your repository settings entirely, wait at least 45 to 60 minutes to ensure the cache clears, and then add it back. Add an explicit CAA record: You noted that you do not have CAA records blocking Let's Encrypt. However, explicitly adding one can sometimes force the validation to succeed, especially with certain registrars like reg.ru that might have unique default behaviors. Add a CAA record for dvs-servis75.ru with the value 0 issue "letsencrypt.org." Verify DNSSEC configuration: Check your reg.ru control panel to ensure DNSSEC is either fully disabled or perfectly configured. A broken DNSSEC chain will cause Let's Encrypt's DNS lookups to fail, resulting in a persistent InvalidDNSError on GitHub's end even if standard HTTP traffic resolves correctly. Submit a specialised support ticket: To get a human GitHub staff member to manually intervene, you must submit a ticket through the GitHub Support portal. Go to support.github.com/contact/pages (or the general contact form if that direct link redirects) and select "Pages" as the category. Explicitly state that your DNS is fully propagated, you are stuck in an InvalidDNSError loop, and you need staff to manually clear the certificate state and trigger a re-issuance. |
|
Hi, Community members can't manually re-trigger certificate issuance. If the DNS checks are clean and HTTPS is still stuck on Before opening a ticket, I'd check these:
dig www.dvs-servis75.ru CNAME +shortIt should return
dig @ns1.reg.ru dvs-servis75.ru A +short
dig @ns2.reg.ru dvs-servis75.ru A +shortFor the setup you've described, both should return the four GitHub Pages IPs:
I also wouldn't add a CAA record just to "force" validation. If you have no CAA records, there's nothing you need to add for Let's Encrypt. If CAA records do exist, make sure they allow HTTPS normally shouldn't stay stuck for several days, so if all of the checks above are clean, I'd open a Support ticket. Include the repo URL, |
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Question
💬 Feature/Topic Area
Pages
Body
My custom domain dvs-servis75.ru for GitHub Pages works over HTTP, but HTTPS certificate provisioning has been stuck on InvalidDNSError for several days.
Repository: https://github.com/sapfirrrr/dvs-chita/
I have verified all DNS requirements per GitHub documentation:
I have tried removing and re-adding the custom domain multiple times, but provisioning still fails. The site works fine over HTTP, only HTTPS fails.
This is a real technical bug, not product feedback. Could a GitHub staff member please manually re-trigger Let's Encrypt certificate issuance for this domain?
Thank you.
All reactions