TLS SNI 01 authentication removed, must upgrade to 0.21.0 to renew

Bug #1745227 reported by Ray Foss
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
python-certbot (Ubuntu)
Fix Released
High
Unassigned
Xenial
Fix Released
High
Unassigned
Artful
Won't Fix
High
Unassigned

Bug Description

https://github.com/certbot/certbot/issues/5405#issuecomment-358524100

TLS-SNI-01 had a CA security issue in shared hosts, as such the letsencrypt CA blocked the auth method. The update is in 0.21.0, until it's pushed out renewing will be more difficult as you'll need to configure webroot renewals.

This affects all current and future versions. I'm in 14.04.5 LTS
I'm on certbot 0.19.0, 20.0-3 is available in The Bionic Beaver

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in python-certbot (Ubuntu):
status: New → Confirmed
Jeremy Bícha (jbicha)
Changed in python-certbot (Ubuntu):
importance: Undecided → High
status: Confirmed → Fix Released
Changed in python-certbot (Ubuntu Xenial):
importance: Undecided → High
status: New → Triaged
Changed in python-certbot (Ubuntu Artful):
importance: Undecided → High
status: New → Triaged
Revision history for this message
Mathew Hodson (mhodson) wrote :

python-certbot (0.23.0-1~ubuntu16.04.1) xenial; urgency=medium

  [ Robie Basak ]
  * This update is part of the set of major updates moving Let's
    Encrypt/Certbot to version 0.23 in 16.04 in order to allow it to
    continue working following the general shutdown of TLS-SNI-01
    validation (LP: #1640978).
  * This new source package takes over the function of
    the previous source package python-letsencrypt, with binary packages
    certbot, python-certbot and python-certbot-doc taking over
    respectively.
  * The following two functional changes are additionally made:
    - Log rotation is switched to logrotate via
      /etc/logrotate.d/certbot, and /etc/letsencrypt/cli.ini is
      introduced to disable internal log rotation to avoid collision.
    - Automatic renewal is enabled via the certbot.timer and
      certbot.service systemd units.

  [ Michael Casadevall ]
  * Backport to Xenial

 -- Robie Basak <email address hidden> Fri, 22 Feb 2019 12:41:51 +0000

Changed in python-certbot (Ubuntu Artful):
status: Triaged → Won't Fix
Changed in python-certbot (Ubuntu Xenial):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.