Pages HTTPS certificate stuck for a-pilot.ru — DNS correct, HTTPS serves *.github.io #209466
Replies: 8 comments
|
💬 Your Product Feedback Has Been Submitted 🎉 Thank you for taking the time to share your insights with us! Your feedback is invaluable as we build a better GitHub experience for all our users. Here's what you can expect moving forward ⏩
Where to look to see what's shipping 👀
What you can do in the meantime 💻
As a member of the GitHub community, your participation is essential. While we can't promise that every suggestion will be implemented, we want to emphasize that your feedback is instrumental in guiding our decisions and priorities. Thank you once again for your contribution to making GitHub even better! We're grateful for your ongoing support and collaboration in shaping the future of our platform. ⭐ |
|
The DNS shown here looks correct for an apex GitHub Pages domain: all four GitHub A records are present, "www" is a CNAME directly to "maxinterquartz.github.io", and there are no AAAA/CAA records interfering with issuance. The interesting part is the TLS result: "openssl s_client -connect a-pilot.ru:443 -servername a-pilot.ru" returns a Let's Encrypt certificate for "*.github.io", not "a-pilot.ru". That suggests the request is reaching GitHub Pages, but the custom-domain certificate has not been provisioned/attached to the Pages TLS endpoint yet. This is consistent with the fact that "Enforce HTTPS" remains unavailable. I'd verify the DNS from multiple resolvers and specifically check for any additional records at the apex, including ALIAS/ANAME, wildcard records, CAA, and IPv6: dig +noall +answer a-pilot.ru A Also test the certificate/SNI independently for both hostnames: openssl s_client -connect a-pilot.ru:443 -servername a-pilot.ru </dev/null 2>/dev/null openssl s_client -connect www.a-pilot.ru:443 -servername www.a-pilot.ru </dev/null 2>/dev/null If those continue to return the GitHub wildcard certificate while the Pages DNS check still reports "InvalidDNSError", I'd stop repeatedly removing/re-adding the domain. At that point the public DNS configuration is not obviously the problem; the useful next step is to determine why GitHub's Pages certificate-provisioning job is not accepting the domain. One thing worth checking is the repository's Pages configuration and domain verification status as well. GitHub recommends verifying the custom domain before adding it to Pages. If all of the above checks are clean, this looks like a GitHub Pages certificate-provisioning issue rather than something that can be fixed by changing the A records again. The relevant GitHub documentation says certificate issuance is handled automatically through Let's Encrypt after the DNS check succeeds, so GitHub would need to investigate/re-trigger the provisioning job if it remains stuck. |
|
Thanks for the detailed response, @PrithwishDas101. I ran all the checks you suggested. DNS recordsTLS certificate for
|
|
Hi @maxinterquartz, thanks for sharing all the detailed troubleshooting results. It definitely looks like you’ve ruled out the common DNS issues, especially with both Hopefully a GitHub staff member can check the Pages certificate provisioning on their side and help get the custom-domain certificate issued. 🤞 Good luck getting it resolved! |
|
The DNS configuration looks consistent with GitHub Pages, and the TLS output is particularly useful here. Since:
this looks less like a basic DNS propagation problem and more like the custom-domain certificate has not been successfully provisioned/attached to the Pages site. One additional diagnostic I'd suggest is checking the certificate from multiple external resolvers/locations and comparing both names: openssl s_client -connect a-pilot.ru:443 -servername a-pilot.ru </dev/null 2>/dev/null |
openssl x509 -noout -subject -issuer -dates -ext subjectAltName
openssl s_client -connect www.a-pilot.ru:443 -servername www.a-pilot.ru </dev/null 2>/dev/null |
openssl x509 -noout -subject -issuer -dates -ext subjectAltNameThe important thing is whether GitHub's edge consistently returns the I'd also check for any less-obvious DNS records, especially: dig a-pilot.ru CAA +short
dig a-pilot.ru AAAA +short
dig www.a-pilot.ru CAA +short
dig www.a-pilot.ru AAAA +shortand verify that there isn't an unexpected DNS provider/CDN/proxy sitting in front of the domain. However, given that you've already removed/re-added the domain multiple times and reproduced the problem after waiting 24–48 hours, repeatedly re-adding the domain probably isn't going to provide much additional information. At this point, the most useful thing GitHub could check internally is the Pages custom-domain/certificate provisioning state for If the public DNS is correct and the Pages site is responding correctly over HTTP, but the certificate never gets associated with the custom domain, this is something that may require GitHub to re-trigger/reset the certificate provisioning state on their side. I'd include the exact |
|
Thanks @md-owais9956 and @varsh23-p for the detailed analysis. Additional DNS checksThe CAA/AAAA results for Timestamped TLS output2026-10-04, ~18:30 UTC The SAN list is the key evidence: @github-staff — could you please check the Pages certificate provisioning state for Repo: https://github.com/maxinterquartz/a-pilot Thank you! |
|
Update: I checked the Pages API and found the root cause. The Combined with:
...this confirms the issue is entirely on GitHub's side: the certificate order is not being created for this domain. @github-staff — could you please check why the Pages certificate provisioning job is not even starting for |
Analysis of Missing
|
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Bug
💬 Feature/Topic Area
Pages
Body
Pages HTTPS certificate stuck for a-pilot.ru — DNS correct, HTTPS serves *.github.io
Hello GitHub Community / GitHub Staff,
I need help with GitHub Pages HTTPS certificate provisioning for my custom domain. I have been manually re-triggering the process for a whole week (removing and re-adding the domain, then waiting 24–48 hours each time), but the certificate is still not obtained despite correct DNS settings.
Details
Current state
200 OK,server: GitHub.com*.github.iocertificate instead of a certificate fora-pilot.ruDNS check unsuccessfulwithInvalidDNSError, even though public DNS returns the correct recordsDNS records (verified via 8.8.8.8, 1.1.1.1, 9.9.9.9)
@: 185.199.108.153, 185.199.109.153, 185.199.110.153, 185.199.111.153www:maxinterquartz.github.io.What I've already tried
Command output
Could a GitHub Staff member please manually re-trigger or unblock the Let's Encrypt certificate provisioning for
a-pilot.ruandwww.a-pilot.ru? I am on a free plan and cannot open a paid support ticket.Screenshots attached: Pages settings and DNS zone on reg.ru.
Thank you!
All reactions