MDContactEmail
can now be specified inside a<MDomain dnsname>
section.- Treating 401 HTTP status codes for orders like 403, since Sectigo
seems to prefer that for accessing oders from other accounts. - When retrieving certificate chains, try to read the response even
if the HTTP Content-Type is unrecognized. - Fixed the renewal process giving up every time on an already existing order
with some invalid domains. Now, if such are seen in a previous order, a new
order is created for a clean start over again. See #268. - Fixed a mixup in md-status handler when static certificate files and
renewal was configured at the same time. - New: experimental support for ACME External Account Binding (EAB).
Use the new directiveMDExternalAccountBinding
to provide the
server with the value for key identifier and hmac as provided by
your CA.
While working on some servers, EAB handling is not uniform across CAs.
First tests with a Sectigo Certificate Manager in demo mode are
successful. But ZeroSSL, for example, seems to regard EAB values as
a one-time-use-only thing, which makes them fail if you create a
seconde account or retry the creation of the first account with
the same EAB.