github fabriziosalmi/certmate v2.42.0
v2.42.0 (a renewal that uses today's settings)

3 hours ago

v2.42.0 (a renewal that uses today's settings)

A renewal now answers its challenge with the settings of today, not those of
the day the certificate was issued. Also fixed: an HTTP-01 certificate with
an alias that could never renew, a CSR-only certificate whose renewal was
recorded as a new certificate, a certbot plugin check that an unrelated AWS
profile could fail, and an audit chain that two processes could fork.

The API contract stays at 2.32. No response changes shape.


Read this before upgrading

Renewals use the wait, webroot and hooks configured now

certbot records the options of the run that issued a certificate and replays
them at every renewal, unless the command line says otherwise. CertMate's
renewal did not pass the DNS propagation wait, the HTTP-01 webroot or the
custom-script hook paths, so each certificate kept the values of its issue
day for its whole life.

  • Raising a provider's wait in Settings now reaches existing
    certificates
    , from their next renewal. Until now it changed only
    certificates issued afterwards. This includes the move of Akamai Edge DNS
    from 90 to 180 seconds in v2.40.0 (#974): certificates issued before it
    kept renewing with 90.
  • Moving a custom-script hook needs only its new path in Settings. The
    documentation used to say to reissue the certificate.
  • An HTTP-01 certificate renews with the webroot CertMate serves today, so
    moving the data directory or changing ACME_CHALLENGES_DIR no longer
    strands it.

Create and renew now pass these options through the same code, and a test
requires the two commands to agree on the challenge for every way of
answering it (#1010).


Fixed

  • HTTP-01 with an alias. Issuance answered HTTP-01 through the webroot and
    stored the alias anyway. Renewal saw the alias, looked for a DNS account
    named http-01, and failed every time (#1010).
  • CSR-only certificates. Every renewal reset the certificate's creation
    date, never recorded renewed_at, and was counted in the creation metrics
    as well as the renewal ones. A renewal now keeps the creation date, records
    when it renewed, and is counted once, as a renewal (#1012).
  • Renewal errors. Webhooks, notifications and the audit record received
    every renewal failure as Exception: Certificate renewal failed: …. The
    prefix is gone (#1012).
  • The certbot plugin check. It ran certbot plugins --prepare, which
    initialises every installed plugin. When AWS_PROFILE named a profile the
    AWS configuration did not have, or that configuration did not parse, the
    Route53 plugin failed to initialise, and CertMate reported that the
    Cloudflare plugin was not installed and refused to issue. The check now
    lists plugins without preparing them, and matches names exactly. Thanks to
    @QuentinBtd (#1011).
  • Audit chain. Two processes starting against the same data directory
    could both write the same sequence number, which leaves the chain
    permanently unverifiable. Seen once in CI. Recovery measured the file
    separately from reading it, and a line written in between was missed. It
    now records the size of exactly what it read (#1009).

Documentation

  • Custom DNS script and DNS providers: renewals use the hook paths
    configured now, in five languages.
  • README: a link to CertMate in 60 seconds,
    a video guide of one-minute shorts.

How it was checked

  • The renewal wait, against Let's Encrypt staging with Cloudflare: issue
    with the wait at 11 s, set it to 17 s, renew. certbot ran with 11 before
    this release and with 17 after it. This test now runs in the release gate.
  • HTTP-01 renewal, against a private ACME CA (step-ca), with the
    scheduler's own renewal job: five expired certificates renewed, and
    certbot's command line carries the current webroot. A new certificate was
    issued on the same bench.
  • The plugin check, inside the v2.41.0 image: three broken AWS
    configurations made the old check deny Cloudflare. The new check reports
    Cloudflare, Route53 and Edge DNS as installed, and an unknown name as not.
  • The audit chain, with two real processes started together: 20 runs out
    of 20 wrote a duplicate sequence number when the second process paused
    between reading and measuring, and none after the fix.
  • CSR renewals and renewal errors, on the certificate manager with a
    certbot stand-in. The new tests fail on v2.41.0 and pass here.

Don't miss a new certmate release

NewReleases is sending notifications on new releases.