github.com/go-acme/lego
v2.7.2+incompatible
#350 most downloaded on Go modules
go-acme/lego
What this package is like to depend on
Last release 7 years ago
no release in 18 months
Ships fairly regularly
a new release about every 2 weeks
Some releases are documented
notes for 11 of 24 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
58 releases · first in 2015
0 releases in the last 12 months
see the full history below
Release timeline
58 releases · Nov 2015 to Jul 2019Releases
latest 58-
v2.7.2+incompatible31 Jul 2019Nothing published for this version
-
v2.7.2-0.20190727050804-58d6d9f4767a+incompatible27 Jul 2019 pre-releaseNothing published for this version
-
v2.7.1+incompatible22 Jul 2019Nothing published for this version
-
v2.7.0+incompatible17 Jul 2019Nothing published for this version
-
v2.6.1-0.20190710175340-09caec4158ed+incompatible10 Jul 2019 pre-releaseNothing published for this version
-
v2.6.1-0.20190624180855-ac65f6c6a9a4+incompatible24 Jun 2019 pre-releaseNothing published for this version
-
v2.6.0+incompatible27 May 2019Nothing published for this version
-
v2.5.1-0.20190509115824-b9bafc582ce3+incompatible09 May 2019 pre-releaseNothing published for this version
-
v2.5.1-0.20190429000304-007888f9dcce+incompatible29 Apr 2019 pre-releaseNothing published for this version
-
v2.5.0+incompatible18 Apr 2019Nothing published for this version
-
v2.4.0+incompatible26 Mar 2019Nothing published for this version
-
v2.3.1-0.20190321144621-b668bde5e4b7+incompatible21 Mar 2019 pre-releaseNothing published for this version
-
v2.3.1-0.20190318164254-3684cc738d37+incompatible18 Mar 2019 pre-releaseNothing published for this version
-
v2.3.1-0.20190312085123-0c87df143e63+incompatible12 Mar 2019 pre-releaseNothing published for this version
-
v2.3.1-0.20190311182922-11ddd5825397+incompatible11 Mar 2019 pre-releaseNothing published for this version
-
v2.3.0+incompatible11 Mar 2019Nothing published for this version
-
v2.2.1-0.20190304181753-67b329e3e370+incompatible04 Mar 2019 pre-releaseNothing published for this version
-
v2.2.1-0.20190209044618-19303d3ac67d+incompatible09 Feb 2019 pre-releaseNothing published for this version
-
v2.2.0+incompatible09 Feb 2019Nothing published for this version
-
v2.1.0+incompatible24 Jan 2019Nothing published for this version
-
v2.0.2-0.20190111231729-ec6c22d70b19+incompatible11 Jan 2019 pre-releaseNothing published for this version
-
v2.0.1+incompatible09 Jan 2019Nothing published for this version
-
v2.0.0+incompatible09 Jan 2019Nothing published for this version
-
v1.2.2-0.20190727050804-58d6d9f4767a27 Jul 2019 pre-releaseNothing published for this version
-
v1.2.2-0.20190318164254-3684cc738d3718 Mar 2019 pre-releaseNothing published for this version
-
v1.2.2-0.20190108215313-891b50656cee08 Jan 2019 pre-releaseNothing published for this version
-
v1.2.2-0.20190103155953-43401f2475dd03 Jan 2019 pre-releaseNothing published for this version
-
v1.2.105 Nov 2018Nothing published for this version
-
v1.2.005 Nov 2018Release notes
Open source →- Release date: 2018-11-04
- Tag: v1.2.0
Added
- [dnsprovider] Add DNS Provider for ConoHa DNS
- [dnsprovider] Add DNS Provider for MyDNS.jp
- [dnsprovider] Add DNS Provider for Selectel
Fixed
- [dnsprovider] netcup: make unmarshalling of api-responses more lenient.
Changed
- [dnsprovider] aurora: change DNS client
- [dnsprovider] azure: update auth to support instance metadata service
- [dnsprovider] dnsmadeeasy: log response body on error
- [lib] TLS-ALPN-01: Update idPeAcmeIdentifierV1, draft refs.
- [lib] Do not send a JWS body when POSTing challenges.
- [lib] Support POST-as-GET.
Release notes
Open source →Added:
- [dnsprovider] Add DNS Provider for ConoHa DNS
- [dnsprovider] Add DNS Provider for MyDNS.jp
- [dnsprovider] Add DNS Provider for Selectel
Fixed:
- [dnsprovider] netcup: make unmarshalling of api-responses more lenient.
Changed:
- [dnsprovider] aurora: change DNS client
- [dnsprovider] azure: update auth to support instance metadata service
- [dnsprovider] dnsmadeeasy: log response body on error
- [lib] TLS-ALPN-01: Update idPeAcmeIdentifierV1, draft refs.
- [lib] Do not send a JWS body when POSTing challenges.
- [lib] Support POST-as-GET.
-
v1.1.017 Oct 2018Release notes
Open source →- Release date: 2018-10-16
- Tag: v1.1.0
Added
- [lib] TLS-ALPN-01 Challenge
- [cli] Add filename parameter
- [dnsprovider] Allow to configure TTL, interval and timeout
- [dnsprovider] Add support for reading DNS provider setup from files
- [dnsprovider] Add DNS Provider for ACME-DNS
- [dnsprovider] Add DNS Provider for ALIYUN DNS
- [dnsprovider] Add DNS Provider for DreamHost
- [dnsprovider] Add DNS provider for hosting.de
- [dnsprovider] Add DNS Provider for IIJ
- [dnsprovider] Add DNS Provider for netcup
- [dnsprovider] Add DNS Provider for NIFCLOUD DNS
- [dnsprovider] Add DNS Provider for SAKURA Cloud
- [dnsprovider] Add DNS Provider for Stackpath
- [dnsprovider] Add DNS Provider for VegaDNS
- [dnsprovider] exec: add EXEC_MODE=RAW support.
- [dnsprovider] cloudflare: support for CF_API_KEY and CF_API_EMAIL
Fixed
- [lib] Don't trust identifiers order.
- [lib] Fix missing issuer certificates from Let's Encrypt
- [dnsprovider] duckdns: fix TXT record update url
- [dnsprovider] duckdns: fix subsubdomain
- [dnsprovider] gcloud: update findTxtRecords to use Name=fqdn and Type=TXT
- [dnsprovider] lightsail: Fix Domain does not exist error
- [dnsprovider] ns1: use the authoritative zone and not the domain name
- [dnsprovider] ovh: check error to avoid panic due to nil client
Changed
- [lib] Submit all dns records up front, then validate serially
Release notes
Open source →Added:
- [lib] TLS-ALPN-01 Challenge
- [cli] Add filename parameter
- [dnsprovider] Allow to configure TTL, interval and timeout
- [dnsprovider] Add support for reading DNS provider setup from files
- [dnsprovider] Add DNS Provider for ACME-DNS
- [dnsprovider] Add DNS Provider for ALIYUN DNS
- [dnsprovider] Add DNS Provider for DreamHost
- [dnsprovider] Add DNS provider for hosting.de
- [dnsprovider] Add DNS Provider for IIJ
- [dnsprovider] Add DNS Provider for netcup
- [dnsprovider] Add DNS Provider for NIFCLOUD DNS
- [dnsprovider] Add DNS Provider for SAKURA Cloud
- [dnsprovider] Add DNS Provider for Stackpath
- [dnsprovider] Add DNS Provider for VegaDNS
- [dnsprovider] exec: add EXEC_MODE=RAW support.
- [dnsprovider] cloudflare: support for CF_API_KEY and CF_API_EMAIL
Fixed:
- [lib] Don't trust identifiers order.
- [lib] Fix missing issuer certificates from Let's Encrypt
- [dnsprovider] duckdns: fix TXT record update url
- [dnsprovider] duckdns: fix subsubdomain
- [dnsprovider] gcloud: update findTxtRecords to use Name=fqdn and Type=TXT
- [dnsprovider] lightsail: Fix Domain does not exist error
- [dnsprovider] ns1: use the authoritative zone and not the domain name
- [dnsprovider] ovh: check error to avoid panic due to nil client
Changed:
- [lib] Submit all dns records up front, then validate serially
-
v1.0.2-0.20181013140146-484f0e5e35de13 Oct 2018 pre-releaseNothing published for this version
-
v1.0.2-0.20180611134559-8f9e90b2a0d511 Jun 2018 pre-releaseNothing published for this version
-
v1.0.131 May 2018Nothing published for this version
-
v1.0.031 May 2018Release notes
Open source →- Release date: 2018-05-30
- Tag: v1.0.0
Changed
- [lib] ACME v2 Support.
- [dnsprovider] Renamed
/providers/dns/googlecloudto/providers/dns/gcloud. - [dnsprovider] Modified Google Cloud provider
gcloud.NewDNSProviderServiceAccountfunction to extract the project id directly from the service account file. - [dnsprovider] Made errors more verbose for the Cloudflare provider.
Release notes
Open source →Changed:
- [lib] ACME v2 Support.
- [dnsprovider] Renamed
/providers/dns/googlecloudto/providers/dns/gcloud. - [dnsprovider] Modified Google Cloud provider
gcloud.NewDNSProviderServiceAccountfunction to extract the project id directly from the service account file. - [dnsprovider] Made errors more verbose for the Cloudflare provider.
-
v0.5.030 May 2018Release notes
Open source →- Release date: 2018-05-29
- Tag: v0.5.0
Added
- [dnsprovider] Add DNS challenge provider
exec - [dnsprovider] Add DNS Provider for Akamai FastDNS
- [dnsprovider] Add DNS Provider for Bluecat DNS
- [dnsprovider] Add DNS Provider for CloudXNS
- [dnsprovider] Add DNS Provider for Duck DNS
- [dnsprovider] Add DNS Provider for Gandi Beta Platform (LiveDNS)
- [dnsprovider] Add DNS Provider for GleSYS API
- [dnsprovider] Add DNS Provider for GoDaddy
- [dnsprovider] Add DNS Provider for Lightsail
- [dnsprovider] Add DNS Provider for Name.com
Fixed
- [dnsprovider] Azure: Added missing environment variable in the comments
- [dnsprovider] PowerDNS: Fix zone URL, add leading slash.
- [dnsprovider] DNSimple: Fix api
- [cli] Correct help text for
--dns-resolversdefault. - [cli] renew/revoke - don't panic on wrong account.
- [lib] Fix zone detection for cross-zone cnames.
- [lib] Use proxies from environment when making outbound http connections.
Changed
- [lib] Users of an effective top-level domain can use the DNS challenge.
- [dnsprovider] Azure: Refactor to work with new Azure SDK version.
- [dnsprovider] Cloudflare and Azure: Adding output of which envvars are missing.
- [dnsprovider] Dyn DNS: Slightly improve provider error reporting.
- [dnsprovider] Exoscale: update to latest egoscale version.
- [dnsprovider] Route53: Use NewSessionWithOptions instead of deprecated New.
Release notes
Open source →Added:
- [dnsprovider] Add DNS challenge provider
exec - [dnsprovider] Add DNS Provider for Akamai FastDNS
- [dnsprovider] Add DNS Provider for Bluecat DNS
- [dnsprovider] Add DNS Provider for CloudXNS
- [dnsprovider] Add DNS Provider for Duck DNS
- [dnsprovider] Add DNS Provider for Gandi Beta Platform (LiveDNS)
- [dnsprovider] Add DNS Provider for GleSYS API
- [dnsprovider] Add DNS Provider for GoDaddy
- [dnsprovider] Add DNS Provider for Lightsail
- [dnsprovider] Add DNS Provider for Name.com
Fixed:
- [dnsprovider] Azure: Added missing environment variable in the comments
- [dnsprovider] PowerDNS: Fix zone URL, add leading slash.
- [dnsprovider] DNSimple: Fix api
- [cli] Correct help text for
--dns-resolversdefault. - [cli] renew/revoke - don't panic on wrong account.
- [lib] Fix zone detection for cross-zone cnames.
- [lib] Use proxies from environment when making outbound http connections.
Changed:
- [lib] Users of an effective top-level domain can use the DNS challenge.
- [dnsprovider] Azure: Refactor to work with new Azure SDK version.
- [dnsprovider] Cloudflare and Azure: Adding output of which envvars are missing.
- [dnsprovider] Dyn DNS: Slightly improve provider error reporting.
- [dnsprovider] Exoscale: update to latest egoscale version.
- [dnsprovider] Route53: Use NewSessionWithOptions instead of deprecated New.
-
v0.4.2-0.20180530171757-9a1f8d748a6e30 May 2018 pre-releaseNothing published for this version
-
v0.4.2-0.20180315120156-a149e7d6506f15 Mar 2018 pre-releaseNothing published for this version
-
v0.4.2-0.20180218152758-bacb545c7a2618 Feb 2018 pre-releaseNothing published for this version
-
v0.4.2-0.20171115100300-b929aa5aab5a15 Nov 2017 pre-releaseNothing published for this version
-
v0.4.126 Sep 2017Release notes
Open source →- Release date: 2017-09-26
- Tag: 0.4.1
Added
- lib: A new DNS provider for OTC.
- lib: The
AWS_HOSTED_ZONE_IDenvironment variable for the Route53 DNS provider to directly specify the zone. - lib: The
RFC2136_TIMEOUTenvironment variable to make the timeout for the RFC2136 provider configurable. - lib: The
GCE_SERVICE_ACCOUNT_FILEenvironment variable to specify a service account file for the Google Cloud DNS provider.
Fixed
- lib: Fixed an authentication issue with the latest Azure SDK.
Release notes
Open source →Added:
- lib: A new DNS provider for OTC.
- lib: The
AWS_HOSTED_ZONE_IDenvironment variable for the Route53 DNS provider to directly specify the zone. - lib: The
RFC2136_TIMEOUTenviroment variable to make the timeout for the RFC2136 provider configurable. - lib: The
GCE_SERVICE_ACCOUNT_FILEenvironment variable to specify a service account file for the Google Cloud DNS provider.
Fixed:
- lib: Fixed an authentication issue with the latest Azure SDK.
-
v0.4.013 Jul 2017Release notes
Open source →- Release date: 2017-07-13
- Tag: 0.4.0
Added
- CLI: The
--http-timeoutswitch. This allows for an override of the default client HTTP timeout. - lib: The
HTTPClientfield. This allows for an override of the default HTTP timeout for library HTTP requests. - CLI: The
--dns-timeoutswitch. This allows for an override of the default DNS timeout for library DNS requests. - lib: The
DNSTimeoutswitch. This allows for an override of the default client DNS timeout. - lib: The
QueryRegistrationfunction onacme.Client. This performs a POST on the client registration's URI and gets the updated registration info. - lib: The
DeleteRegistrationfunction onacme.Client. This deletes the registration as currently configured in the client. - lib: The
ObtainCertificateForCSRfunction onacme.Client. The function allows to request a certificate for an already existing CSR. - CLI: The
--csrswitch. Allows to use already existing CSRs for certificate requests on the command line. - CLI: The
--pemflag. This will change the certificate output, so it outputs a .pem file concatenating the .key and .crt files together. - CLI: The
--dns-resolversflag. Allows for users to override the default DNS servers used for recursive lookup. - lib: Added a memcached provider for the HTTP challenge.
- CLI: The
--memcached-hostflag. This allows to use memcached for challenge storage. - CLI: The
--must-stapleflag. This enables OCSP must staple in the generated CSR. - lib: The library will now honor entries in your resolv.conf.
- lib: Added a field
IssuerCertificateto theCertificateResourcestruct. - lib: A new DNS provider for OVH.
- lib: A new DNS provider for DNSMadeEasy.
- lib: A new DNS provider for Linode.
- lib: A new DNS provider for AuroraDNS.
- lib: A new DNS provider for NS1.
- lib: A new DNS provider for Azure DNS.
- lib: A new DNS provider for Rackspace DNS.
- lib: A new DNS provider for Exoscale DNS.
- lib: A new DNS provider for DNSPod.
Changed
- lib: Exported the
PreCheckDNSfield so library users can manage the DNS check in tests. - lib: The library will now skip challenge solving if a valid Authz already exists.
Removed
- lib: The library will no longer check for auto-renewed certificates. This has been removed from the spec and is not supported in Boulder.
Fixed
- lib: Fix a problem with the Route53 provider where it was possible the verification was published to a private zone.
- lib: Loading an account from file should fail if an integral part is nil
- lib: Fix a potential issue where the Dyn provider could resolve to an incorrect zone.
- lib: If a registration encounters a conflict, the old registration is now recovered.
- CLI: The account.json file no longer has the executable flag set.
- lib: Made the client registration more robust in case of a 403 HTTP response.
- lib: Fixed an issue with zone lookups when they have a CNAME in another zone.
- lib: Fixed the lookup for the authoritative zone for Google Cloud.
- lib: Fixed a race condition in the nonce store.
- lib: The Google Cloud provider now removes old entries before trying to add new ones.
- lib: Fixed a condition where we could stall due to an early error condition.
- lib: Fixed an issue where Authz object could end up in an active state after an error condition.
Release notes
Open source →Added:
- CLI: The
--http-timeoutswitch. This allows for an override of the default client HTTP timeout. - lib: The
HTTPClientfield. This allows for an override of the default HTTP timeout for library HTTP requests. - CLI: The
--dns-timeoutswitch. This allows for an override of the default DNS timeout for library DNS requests. - lib: The
DNSTimeoutswitch. This allows for an override of the default client DNS timeout. - lib: The
QueryRegistrationfunction onacme.Client. This performs a POST on the client registration's URI and gets the updated registration info. - lib: The
DeleteRegistrationfunction onacme.Client. This deletes the registration as currently configured in the client. - lib: The
ObtainCertificateForCSRfunction onacme.Client. The function allows to request a certificate for an already existing CSR. - CLI: The
--csrswitch. Allows to use already existing CSRs for certificate requests on the command line. - CLI: The
--pemflag. This will change the certificate output so it outputs a .pem file concatanating the .key and .crt files together. - CLI: The
--dns-resolversflag. Allows for users to override the default DNS servers used for recursive lookup. - lib: Added a memcached provider for the HTTP challenge.
- CLI: The
--memcached-hostflag. This allows to use memcached for challenge storage. - CLI: The
--must-stapleflag. This enables OCSP must staple in the generated CSR. - lib: The library will now honor entries in your resolv.conf.
- lib: Added a field
IssuerCertificateto theCertificateResourcestruct. - lib: A new DNS provider for OVH.
- lib: A new DNS provider for DNSMadeEasy.
- lib: A new DNS provider for Linode.
- lib: A new DNS provider for AuroraDNS.
- lib: A new DNS provider for NS1.
- lib: A new DNS provider for Azure DNS.
- lib: A new DNS provider for Rackspace DNS.
- lib: A new DNS provider for Exoscale DNS.
- lib: A new DNS provider for DNSPod.
Changed:
- lib: Exported the
PreCheckDNSfield so library users can manage the DNS check in tests. - lib: The library will now skip challenge solving if a valid Authz already exists.
Removed:
- lib: The library will no longer check for auto renewed certificates. This has been removed from the spec and is not supported in Boulder.
Fixed:
- lib: Fix a problem with the Route53 provider where it was possible the verification was published to a private zone.
- lib: Loading an account from file should fail if a integral part is nil
- lib: Fix a potential issue where the Dyn provider could resolve to an incorrect zone.
- lib: If a registration encounteres a conflict, the old registration is now recovered.
- CLI: The account.json file no longer has the executable flag set.
- lib: Made the client registration more robust in case of a 403 HTTP response.
- lib: Fixed an issue with zone lookups when they have a CNAME in another zone.
- lib: Fixed the lookup for the authoritative zone for Google Cloud.
- lib: Fixed a race condition in the nonce store.
- lib: The Google Cloud provider now removes old entries before trying to add new ones.
- lib: Fixed a condition where we could stall due to an early error condition.
- lib: Fixed an issue where Authz object could end up in an active state after an error condition.
-
v0.3.2-0.20170505141259-aaa8e70aec5805 May 2017 pre-releaseNothing published for this version
-
v0.3.2-0.20160613233155-a9d8cec0e65613 Jun 2016 pre-releaseNothing published for this version
-
v0.3.119 Apr 2016Release notes
Open source →- Release date: 2016-04-19
- Tag: 0.3.1
Added
- lib: A new DNS provider for Vultr.
Fixed
- lib: DNS Provider for DigitalOcean could not handle subdomains properly.
- lib: handleHTTPError should only try to JSON decode error messages with the right content type.
- lib: The propagation checker for the DNS challenge would not retry on send errors.
Release notes
Open source →Added:
- lib: A new DNS provider for Vultr.
Fixed:
- lib: DNS Provider for DigitalOcean could not handle subdomains properly.
- lib: handleHTTPError should only try to JSON decode error messages with the right content type.
- lib: The propagation checker for the DNS challenge would not retry on send errors.
-
v0.3.019 Mar 2016Release notes
Open source →- Release date: 2016-03-19
- Tag: 0.3.0
Added
- CLI: The
--dnsswitch. To include the DNS challenge for consideration. When using this switch, all other solvers are disabled. Supported are the following solvers: cloudflare, digitalocean, dnsimple, dyn, gandi, googlecloud, namecheap, route53, rfc2136 and manual. - CLI: The
--accept-tosswitch. Indicates your acceptance of the Let's Encrypt terms of service without prompting you. - CLI: The
--webrootswitch. The HTTP-01 challenge may now be completed by dropping a file into a webroot. When using this switch, all other solvers are disabled. - CLI: The
--key-typeswitch. This replaces the--rsa-key-sizeswitch and supports the following key types: EC256, EC384, RSA2048, RSA4096 and RSA8192. - CLI: The
--dnshelpswitch. This displays a more in-depth help topic for DNS solvers. - CLI: The
--no-bundlesub switch for therunandrenewcommands. When this switch is set, the CLI will not bundle the issuer certificate with your certificate. - lib: A new type for challenge identifiers
Challenge - lib: A new interface for custom challenge providers
acme.ChallengeProvider - lib: A new interface for DNS-01 providers to allow for custom timeouts for the validation function
acme.ChallengeProviderTimeout - lib: SetChallengeProvider function. Pass a challenge identifier and a Provider to replace the default behaviour of a challenge.
- lib: The DNS-01 challenge has been implemented with modular solvers using the
ChallengeProviderinterface. Included solvers are: cloudflare, digitalocean, dnsimple, gandi, namecheap, route53, rfc2136 and manual. - lib: The
acme.KeyTypetype was added and is used for the configuration of crypto parameters for RSA and EC keys. Valid KeyTypes are: EC256, EC384, RSA2048, RSA4096 and RSA8192.
Changed
- lib: ExcludeChallenges now expects to be passed an array of
Challengetypes. - lib: HTTP-01 now supports custom solvers using the
ChallengeProviderinterface. - lib: TLS-SNI-01 now supports custom solvers using the
ChallengeProviderinterface. - lib: The
GetPrivateKeyfunction in theacme.Userinterface is now expected to return acrypto.PrivateKeyinstead of anrsa.PrivateKeyfor EC compat. - lib: The
acme.NewClientfunction now expects anacme.KeyTypeinstead of the keyBits parameter.
Removed
- CLI: The
rsa-key-sizeswitch was removed in favor ofkey-typeto support EC keys.
Fixed
- lib: Fixed a race condition in HTTP-01
- lib: Fixed an issue where status codes on ACME challenge responses could lead to no action being taken.
- lib: Fixed a regression when calling the Renew function with a SAN certificate.
Release notes
Open source →Added:
- CLI: The
--dnsswitch. To include the DNS challenge for consideration. When using this switch, all other solvers are disabled. Supported are the following solvers: cloudflare, digitalocean, dnsimple, dyn, gandi, googlecloud, namecheap, route53, rfc2136 and manual. - CLI: The
--accept-tosswitch. Indicates your acceptance of the Let's Encrypt terms of service without prompting you. - CLI: The
--webrootswitch. The HTTP-01 challenge may now be completed by dropping a file into a webroot. When using this switch, all other solvers are disabled. - CLI: The
--key-typeswitch. This replaces the--rsa-key-sizeswitch and supports the following key types: EC256, EC384, RSA2048, RSA4096 and RSA8192. - CLI: The
--dnshelpswitch. This displays a more in-depth help topic for DNS solvers. - CLI: The
--no-bundlesub switch for therunandrenewcommands. When this switch is set, the CLI will not bundle the issuer certificate with your certificate. - lib: A new type for challenge identifiers
Challenge - lib: A new interface for custom challenge providers
acme.ChallengeProvider - lib: A new interface for DNS-01 providers to allow for custom timeouts for the validation function
acme.ChallengeProviderTimeout - lib: SetChallengeProvider function. Pass a challenge identifier and a Provider to replace the default behaviour of a challenge.
- lib: The DNS-01 challenge has been implemented with modular solvers using the
ChallengeProviderinterface. Included solvers are: cloudflare, digitalocean, dnsimple, gandi, namecheap, route53, rfc2136 and manual. - lib: The
acme.KeyTypetype was added and is used for the configuration of crypto parameters for RSA and EC keys. Valid KeyTypes are: EC256, EC384, RSA2048, RSA4096 and RSA8192.
Changed
- lib: ExcludeChallenges now expects to be passed an array of
Challengetypes. - lib: HTTP-01 now supports custom solvers using the
ChallengeProviderinterface. - lib: TLS-SNI-01 now supports custom solvers using the
ChallengeProviderinterface. - lib: The
GetPrivateKeyfunction in theacme.Userinterface is now expected to return acrypto.PrivateKeyinstead of anrsa.PrivateKeyfor EC compat. - lib: The
acme.NewClientfunction now expects anacme.KeyTypeinstead of the keyBits parameter.
Removed
- CLI: The
rsa-key-sizeswitch was removed in favor ofkey-typeto support EC keys.
Fixed
- lib: Fixed a race condition in HTTP-01
- lib: Fixed an issue where status codes on ACME challenge responses could lead to no action being taken.
- lib: Fixed a regression when calling the Renew function with a SAN certificate.
-
v0.2.1-0.20160315103823-0886c377031515 Mar 2016 pre-releaseNothing published for this version
-
v0.2.1-0.20160220002412-7dcfb4a92bd620 Feb 2016 pre-releaseNothing published for this version
-
v0.2.1-0.20160124211050-617dd4d37cb924 Jan 2016 pre-releaseNothing published for this version
-
v0.2.009 Jan 2016Release notes
Open source →- Release date: 2016-01-09
- Tag: 0.2.0
Added
- CLI: The
--excludeor-xswitch. To exclude a challenge from being solved. - CLI: The
--httpswitch. To set the listen address and port of HTTP based challenges. Supportshost:portand:portfor any interface. - CLI: The
--tlsswitch. To set the listen address and port of TLS based challenges. Supportshost:portand:portfor any interface. - CLI: The
--reuse-keyswitch for therenewoperation. This lets you reuse an existing private key for renewals. - lib: ExcludeChallenges function. Pass an array of challenge identifiers to exclude them from solving.
- lib: SetHTTPAddress function. Pass a port to set the listen port for HTTP based challenges.
- lib: SetTLSAddress function. Pass a port to set the listen port of TLS based challenges.
- lib: acme.UserAgent variable. Use this to customize the user agent on all requests sent by lego.
Changed
- lib: NewClient does no longer accept the optPort parameter
- lib: ObtainCertificate now returns a SAN certificate if you pass more than one domain.
- lib: GetOCSPForCert now returns the parsed OCSP response instead of just the status.
- lib: ObtainCertificate has a new parameter
privKey crypto.PrivateKeywhich lets you reuse an existing private key for new certificates. - lib: RenewCertificate now expects the PrivateKey property of the CertificateResource to be set only if you want to reuse the key.
Removed
- CLI: The
--portswitch was removed. - lib: RenewCertificate does no longer offer to also revoke your old certificate.
Fixed
- CLI: Fix logic using the
--daysparameter for renew
Release notes
Open source →Added:
- CLI: The
--excludeor-xswitch. To exclude a challenge from being solved. - CLI: The
--httpswitch. To set the listen address and port of HTTP based challenges. Supportshost:portand:portfor any interface. - CLI: The
--tlsswitch. To set the listen address and port of TLS based challenges. Supportshost:portand:portfor any interface. - CLI: The
--reuse-keyswitch for therenewoperation. This lets you reuse an existing private key for renewals. - lib: ExcludeChallenges function. Pass an array of challenge identifiers to exclude them from solving.
- lib: SetHTTPAddress function. Pass a port to set the listen port for HTTP based challenges.
- lib: SetTLSAddress function. Pass a port to set the listen port of TLS based challenges.
- lib: acme.UserAgent variable. Use this to customize the user agent on all requests sent by lego.
Changed:
- lib: NewClient does no longer accept the optPort parameter
- lib: ObtainCertificate now returns a SAN certificate if you pass more then one domain.
- lib: GetOCSPForCert now returns the parsed OCSP response instead of just the status.
- lib: ObtainCertificate has a new parameter
privKey crypto.PrivateKeywhich lets you reuse an existing private key for new certificates. - lib: RenewCertificate now expects the PrivateKey property of the CertificateResource to be set only if you want to reuse the key.
Removed:
- CLI: The
--portswitch was removed. - lib: RenewCertificate does no longer offer to also revoke your old certificate.
Fixed:
- CLI: Fix logic using the
--daysparameter for renew
-
v0.1.118 Dec 2015Release notes
Open source →- Release date: 2015-12-18
- Tag: 0.1.1
Added
- CLI: Added a way to automate renewal through a cronjob using the --days parameter to renew
Changed
- lib: Improved log output on challenge failures.
Fixed
- CLI: The short parameter for domains would not get accepted
- CLI: The cli did not return proper exit codes on error library errors.
- lib: RenewCertificate did not properly renew SAN certificates.
Security
- lib: Fix possible DOS on GetOCSPForCert
Release notes
Open source →Added:
- CLI: Added a way to automate renewal through a cronjob using the --days parameter to renew
Changed:
- lib: Improved log output on challenge failures.
Fixed:
- CLI: The short parameter for domains would not get accepted
- CLI: The cli did not return proper exit codes on error library errors.
- lib: RenewCertificate did not properly renew SAN certificates.
Security
- lib: Fix possible DOS on GetOCSPForCert
-
v0.1.003 Dec 2015 -
v0.0.0-20190731152208-295dd66f2aa531 Jul 2019 pre-releaseNothing published for this version
-
v0.0.0-20190727050804-58d6d9f4767a27 Jul 2019 pre-releaseNothing published for this version
-
v0.0.0-20190509115824-b9bafc582ce309 May 2019 pre-releaseNothing published for this version
-
v0.0.0-20190319155005-8ed39fe981af19 Mar 2019 pre-releaseNothing published for this version
-
v0.0.0-20190111231729-ec6c22d70b1911 Jan 2019 pre-releaseNothing published for this version
-
v0.0.0-20161024090318-4bb8bea031eb24 Oct 2016 pre-releaseNothing published for this version
-
v0.0.0-20151113192015-5f566d2e0cb313 Nov 2015 pre-releaseNothing published for this version