SSL certificate not renewing/reissuing for custom domain - shows "Ready" but expired cert still served

Update: Resolved

We tried switching from CNAME to A/AAAA records and did another remove+add cycle — still didn’t work.

Then we added the optional ACME challenge CNAME record:
CNAME _acme-challenge.xxx → xxx.flydns.net

After that, the certificate was issued successfully and the app is back up.

Still unclear why:

  • Auto-renewal stopped working when it had renewed fine in October
  • Why it did show everything is fine and would auto-renew but effectively didn’t

@khuezy Sadly I can’t take a look myself and the admin team is in another timezone.
@roadmr Can I send you the details in private somehow? They asked me to redact the public domain.