v2.42.0 (a renewal that uses today's settings)
A renewal now answers its challenge with the settings of today, not those of
the day the certificate was issued. Also fixed: an HTTP-01 certificate with
an alias that could never renew, a CSR-only certificate whose renewal was
recorded as a new certificate, a certbot plugin check that an unrelated AWS
profile could fail, and an audit chain that two processes could fork.
The API contract stays at 2.32. No response changes shape.
Read this before upgrading
Renewals use the wait, webroot and hooks configured now
certbot records the options of the run that issued a certificate and replays
them at every renewal, unless the command line says otherwise. CertMate's
renewal did not pass the DNS propagation wait, the HTTP-01 webroot or the
custom-script hook paths, so each certificate kept the values of its issue
day for its whole life.
- Raising a provider's wait in Settings now reaches existing
certificates, from their next renewal. Until now it changed only
certificates issued afterwards. This includes the move of Akamai Edge DNS
from 90 to 180 seconds in v2.40.0 (#974): certificates issued before it
kept renewing with 90. - Moving a custom-script hook needs only its new path in Settings. The
documentation used to say to reissue the certificate. - An HTTP-01 certificate renews with the webroot CertMate serves today, so
moving the data directory or changingACME_CHALLENGES_DIRno longer
strands it.
Create and renew now pass these options through the same code, and a test
requires the two commands to agree on the challenge for every way of
answering it (#1010).
Fixed
- HTTP-01 with an alias. Issuance answered HTTP-01 through the webroot and
stored the alias anyway. Renewal saw the alias, looked for a DNS account
namedhttp-01, and failed every time (#1010). - CSR-only certificates. Every renewal reset the certificate's creation
date, never recordedrenewed_at, and was counted in the creation metrics
as well as the renewal ones. A renewal now keeps the creation date, records
when it renewed, and is counted once, as a renewal (#1012). - Renewal errors. Webhooks, notifications and the audit record received
every renewal failure asException: Certificate renewal failed: …. The
prefix is gone (#1012). - The certbot plugin check. It ran
certbot plugins --prepare, which
initialises every installed plugin. WhenAWS_PROFILEnamed a profile the
AWS configuration did not have, or that configuration did not parse, the
Route53 plugin failed to initialise, and CertMate reported that the
Cloudflare plugin was not installed and refused to issue. The check now
lists plugins without preparing them, and matches names exactly. Thanks to
@QuentinBtd (#1011). - Audit chain. Two processes starting against the same data directory
could both write the same sequence number, which leaves the chain
permanently unverifiable. Seen once in CI. Recovery measured the file
separately from reading it, and a line written in between was missed. It
now records the size of exactly what it read (#1009).
Documentation
- Custom DNS script and DNS providers: renewals use the hook paths
configured now, in five languages. - README: a link to CertMate in 60 seconds,
a video guide of one-minute shorts.
How it was checked
- The renewal wait, against Let's Encrypt staging with Cloudflare: issue
with the wait at 11 s, set it to 17 s, renew. certbot ran with 11 before
this release and with 17 after it. This test now runs in the release gate. - HTTP-01 renewal, against a private ACME CA (step-ca), with the
scheduler's own renewal job: five expired certificates renewed, and
certbot's command line carries the current webroot. A new certificate was
issued on the same bench. - The plugin check, inside the v2.41.0 image: three broken AWS
configurations made the old check deny Cloudflare. The new check reports
Cloudflare, Route53 and Edge DNS as installed, and an unknown name as not. - The audit chain, with two real processes started together: 20 runs out
of 20 wrote a duplicate sequence number when the second process paused
between reading and measuring, and none after the fix. - CSR renewals and renewal errors, on the certificate manager with a
certbot stand-in. The new tests fail on v2.41.0 and pass here.