GitHub Pages: TLS certificate stuck in "new", health check reports ResolvTimeout for georgy-tech.ru #209317
Replies: 1 comment
|
Your records look fine from here: NS What stands out is a direct query against the authoritative nameservers: That matches the health output you already have ( Same pattern as several .ru Pages threads this week: #208857, #209098, #208881. On #208857 the owner left REG.RU as registrar, moved DNS hosting to Cloudflare (free plan, records DNS only / not proxied), recreated the four A records + www CNAME, waited until Practical path: that Cloudflare move, then one remove/re-add — or keep waiting on a support ticket. Avoid repeated remove/re-add without a DNS change; it only restarts the queue. |
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Question
💬 Feature/Topic Area
Pages
Body
Repository: Georgy-ITech/site-portfolio
Custom domain: georgy-tech.ru (www.georgy-tech.ru as alternate)
The HTTPS certificate has been stuck in state "new" for over 24 hours ("This domain was recently added. The certificate request process will begin shortly.").
The Pages health API (GET /repos/Georgy-ITech/site-portfolio/pages/health) returns:
dns_resolves: false
caa_error: Dnsruby::ResolvTimeout (yesterday: Dnsruby::ServFail)
reason: InvalidDNSError
DNS is configured per the docs and resolves correctly from public resolvers (Google 8.8.8.8, Cloudflare 1.1.1.1) and directly from the authoritative servers (ns1.reg.ru, ns2.reg.ru), over UDP and TCP:
georgy-tech.ru A 185.199.108.153, 185.199.109.153, 185.199.110.153, 185.199.111.153
www.georgy-tech.ru CNAME georgy-itech.github.io
No AAAA, no CAA records (authoritative servers return NOERROR/NODATA for CAA), no DNSSEC.
The domain has been removed and re-added once. Could you check why your resolver times out on this domain and re-queue the certificate request?
All reactions