NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2340 most downloaded on PyPI
ACME protocol implementation in Python
Last release 16 days ago
01 Sep 2026
Ships on a steady schedule
a new release about every 2 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
154 releases · first in 2015
certbot-auto was deprecated on Debian based systems.
--key-type has been added to specify 'rsa' or 'ecdsa' (default 'rsa').--elliptic-curve has been added which takes an NIST/SECG elliptic curve. Any of
secp256r1, secp284r1 and secp521r1 are accepted values.certbot certficates lists the which type of the private key that was used
for the private key.--manual-public-ip-logging-ok is now a no-op, generates a
deprecation warning, and will be removed in a future release.More details about these changes can be found on our GitHub repo.
certbot-auto was deprecated on all systems except for those based on Debian or RHEL.
One column per quarter.
--preconfigured-renewal flag, for packager use only.
See the packaging guide.python -m pytest to test Certbot
instead of the deprecated python setup.py test setuptools approach.server_name case-sensitivity in the nginx plugin.acme library required by Certbot was corrected.
In the previous release, Certbot said it required acme>=1.6.0 when it
actually required acme>=1.8.0 to properly support removing contact
information from an ACME account.More details about these changes can be found on our GitHub repo.
Added the ability to remove email and phone contact information from an account using update_account --register-unsafely-without-email
update_account --register-unsafely-without-emailacme library can now tell the ACME server to clear contact information by passing an empty
tuple to the contact field of a Registration message.*** stack smashing detected *** error in the Certbot snap on some systems.More details about these changes can be found on our GitHub repo.
The prefixed form is still supported but is deprecated, and will be removed in a future release.
plugin_name instead of dist_name:plugin_name):
this concerns the plugin name, CLI flags, and keys in credential files.
The prefixed form is still supported but is deprecated, and will be removed in a future release.--nginx-sleep-seconds (default 1) for environments where nginx takes a long time to reload.More details about these changes can be found on our GitHub repo.
Read acmev1 Let's Encrypt server URL from renewal config as acmev2 URL to prepare for impending acmev1 deprecation.
certbot.compat.filesystem.umask is a drop-in replacement for os.umask
implementing umask for both UNIX and Windows systems.acme module.--preferred-chain <issuer CN>. If a CA offers multiple certificate chains,
it may be used to indicate to Certbot which chain should be preferred.
--preferred-chain "DST Root CA X3"022 is applied by default: all files/directories are not writable by anyone
other than the user running Certbot and the system/admin users.StrictVersion, but LooseVersion to check version requirements with setuptools,
to fix some packaging issues with libraries respecting PEP404 for version string,
with doesn't match StrictVersion requirements.More details about these changes can be found on our GitHub repo.
Require explicit confirmation of snap plugin permissions before connecting.
More details about these changes can be found on our GitHub repo.
Deprecate certbot-auto on Gentoo, macOS, and FreeBSD.
certbot certificatesmanual plugin: CERTBOT_REMAINING_CHALLENGES is equal to the number of challenges
remaining after the current challenge, CERTBOT_ALL_DOMAINS is a comma-separated list
of all domains challenged for the current certificate.acme library. Support of this
challenge in the Certbot client is planned to be added in a future release.*.ps1 and *.bat as valid scripts for Certbot.mock dependency is now conditional on Python 2 in all of our packages.acme library no longer sends the
resource field in any requests or the type field when responding to challenges.More details about these changes can be found on our GitHub repo.
Added certbot.ocsp Certbot's API. The certbot.ocsp module can be used to determine the OCSP status of certificates.
Read-only file system
error when creating challenge directories (issue #7165).More details about these changes can be found on our GitHub repo.
Added support for Cloudflare's limited-scope API Tokens
SSLCompression off setting to follow Mozilla recommendations in Apache.More details about these changes can be found on our GitHub repo.
Support for Python 3.4 in Certbot and its ACME library is deprecated and will be removed in the next release of Certbot. certbot-auto users on x86_64…
acme to retry a POST-as-GET
request as a GET request when the targeted ACME CA server seems to not support
POST-as-GET requests.More details about these changes can be found on our GitHub repo.
certbot-auto has deprecated support for systems using OpenSSL 1.0.1 that are not running on x86-64. This primarily affects RHEL 6 based systems.
docs extras for the certbot-apache and certbot-nginx packages
have been removed.config_changes subcommand has been removedcertbot.plugins.common.TLSSNI01 has been removed.acme.challenges and acme.standalone
have been removed.certbot.client.view_config_changes,
certbot.main.config_changes,
certbot.plugins.common.Installer.view_config_changes,
certbot.reverter.Reverter.view_config_changes, and
certbot.util.get_systemd_os_info have been removedregister --update-registration subcommand has been removedAdded back support for Python 3.4 to Certbot components and certbot-auto due to a bug when requiring Python 2.7 or 3.5+ on RHEL 6 based systems.
More details about these changes can be found on our GitHub repo.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →