NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #5622 most downloaded on PyPI
Cloudflare DNS Authenticator plugin for Certbot
Last release 1 months ago
01 Sep 2026
Ships on a steady schedule
a new release about every 2 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
116 releases · first in 2017
certbot and its acme library now require cryptography>=47.0.0.
Fixed nginx configuration parsing when comments appear between tokens of a multi-line directive.
One column per quarter.
certbot now requires version 1.7+ of the library distro and certbot-dns-cloudflare requires 4.0+ of the Cloudflare Python library.
The certbot.ocsp module has been deprecated and will be removed in the next major release. This is not a change to Certbot's OCSP functionality. The c…
The webroot plugin now supports IP address issuance.
We rebuilt our snaps to include updated versions our dependencies.
A few largely unused functions/types have been deprecated in our effort to remove our pyOpenSSL dependency:
--preferred-profile shortlived. (#10465)certbot certonly or certbot run to get a new cert. This change was made for pre and post directory hooks in our 3.2.0 release so this change unifies Certbot's behavior here. (#9978)certbot.crypto_util.get_sans_from_cert
* Deprecated: certbot.crypto_util.get_names_from_cert
* Deprecated: certbot.crypto_util.get_names_from_req
* Deprecated: certbot.crypto_util.import_csr_file (and replaced by certbot.crypto_util.read_csr_file)
* Deprecated: acme.crypto_util.Format (#10433)achallenges.KeyAuthorizationAnnotatedChallenge, achallenges.DNS, and achallenges.Other have a new field identifier, of type acme.messages.Identifier. This should be used in place of the domain field, which is now deprecated both as an attribute and during object creation. (#10491)domain to identifier, and can now receive string-formatted IP addresses in addition to domain names. (#10495)Fixed a regression that caused certbot to crash if multiple --webroot-path values were set on the command line.
Support for Python 3.14 was added.
vhost_combined and vhost_common log formats from included Apache
configuration file. (#9769)The function acme.crypto_util.make_self_signed_cert was deprecated and will be removed in a future release.
acme.crypto_util.make_self_signed_cert was deprecated and will
be removed in a future release.
(#10466)certbot enhance and they didn't have matching
SSL server blocks. certbot enhance now requires the user to have a matching
SSL server block to enable HSTS or OCSP stapling enhancements.
(#10455)Removed a number of deprecated classes/interfaces
uv as a test dependency, and switched most pip invocations to uv pip for faster installs.
(#10428)Removed final instances of pyopenssl x509 and PKey objects
acme.crypto_util.SSLSocketacme.crypto_util.probe_sniRemoved a number of deprecated classes/interfaces
acme.challenges.TLSALPN01Responseacme.challenges.TLSALPN01acme.standalone.TLSServeracme.standalone.TLSALPN01Server(#10274)
certbot.ocsp.RevocationChecker.init no longer accepts the parameter
enforce_openssl_binary_usage and always uses the cryptography Python
library for OCSP checking.
(#10291)
Python 3.9 support was removed. (#10389)
Migrated most functionality from certbot/setup.py to
certbot/pyproject.toml
(#10402)
Migrated most functionality from setup.py to pyproject.toml for acme,
certbot-apache, and certbot-nginx.
(#10417)
Migrated most functionality from setup.py to pyproject.toml for certbot
dns plugins. (#10425)
Updated apache TLS configuration options based on changes to Mozilla's intermediate configuration recommendations.
DHE-RSA-CHACHA20-POLY1305 to SSLCipherSuite list for better
complianceSSLOpenSSLConfCmd so FFDH won't be used with
OpenSSL 3.0(#10443)
Deprecated acme.crypto_util.probe_sni
--eab-hmac-alg parameter to support custom HMAC algorithm for
External Account Binding.
(#10281)pytz.
(#10350)acme.crypto_util.probe_sni
(#10386)When a CA fails to issue a certificate after finalization, print the ACME error from the order
More details about these changes can be found on our GitHub repo.
Deprecated acme.challenges.TLSALPN01Response
certbot renew will automatically check ARI when using an ACME server that supports it,
and may renew early based on the ARI information. For Let's Encrypt certificates this
will typically cause renewal at around 2/3rds of the certificate's lifetime, even if
the renew_before_expiry field of a lineage renewal config is set a later date.acme.challenges.TLSALPN01Responseacme.challenges.TLSALPN01alpn_protocols from acme.crypto_util.probe_sniacme.crypto_util.SSLSocketacme.standalone.TLSServeracme.standalone.TLSALPN01Serverenforce_openssl_binary_usage from certbot.ocsp.RevocationChecker.orderNotReady response, polls until order status is
ready, and resubmits finalization request before polling for valid to download
certificate. This conforms to RFC 8555 more accurately and avoids race conditions where
all authorizations are fulfilled but order has not yet transitioned to ready state on
the server when the finalization request is sent. It also respects retry-after when
polling for finalization readiness.renew_before_expiry could not be
shorter than certbot's default renewal time. If the server does not provide an ARI
response, renew_before_expiry will continue to override certbot's default. However,
an early ARI response will override a later renew_before_expiry time, to account for
notifications in case of certificate revocation, especially with the impending deprecation
of OCSP (https://letsencrypt.org/2024/12/05/ending-ocsp/). To force a later date, users
can replace certbot's default cron job and/or systemd timer with one of their own timing.More details about these changes can be found on our GitHub repo.
The --preferred-profile and --required-profile flags allow requesting a profile. https://datatracker.ietf.org/doc/draft-aaron-acme-profiles/
Certificates now renew with 1/3rd of lifetime left (or 1/2 of lifetime left, if the lifetime is shorter than 10 days). This is a change from a hardcoded renewal at 30 days before expiration. The config field renew_before_expiry still overrides this default.
removed acme.crypto_util._pyopenssl_cert_or_req_all_names
removed acme.crypto_util._pyopenssl_cert_or_req_san
removed acme.crypto_util.dump_pyopenssl_chain
removed acme.crypto_util.gen_ss_cert
removed certbot.crypto_util.dump_pyopenssl_chain
removed certbot.crypto_util.pyopenssl_load_certificate
RewriteEngine on directive added during apache http01 authentication
to the end of the virtual host, so that it overwrites any RewriteEngine off
directives that already exist and allows redirection to the challenge URL.More details about these changes can be found on our GitHub repo.
deprecated acme.crypto_util.dump_pyopenssl_chain
acme.crypto_util.dump_pyopenssl_chainacme.crypto_util._pyopenssl_cert_or_req_all_namesacme.crypto_util._pyopenssl_cert_or_req_sancertbot.crypto_util.dump_pyopenssl_chaincertbot.crypto_util.pyopenssl_load_certificateMore details about these changes can be found on our GitHub repo.
Deprecated gen_ss_cert in acme.crypto_util as it uses deprecated pyOpenSSL API.
gen_ss_cert in acme.crypto_util as it uses deprecated
pyOpenSSL API.make_self_signed_cert to acme.crypto_util to replace `gen_ss_cert.renewFalse as default when it can be set via cli.ini instead of NoneMore details about these changes can be found on our GitHub repo.
Python 3.8 support was removed.
More details about these changes can be found on our GitHub repo.
Removed a CryptographyDeprecationWarning that was being displayed to users when checking OCSP status.
More details about these changes can be found on our GitHub repo.
Support for Python 3.8 was deprecated and will be removed in our next planned release.
csr_dir and key_dir attributes on
certbot.configuration.NamespaceConfig were removed.--manual-public-ip-logging-ok command line flag was removed.--dns-route53-propagation-seconds command line flag was removed.certbot_dns_route53.authenticator module has been removed. This should
not affect any users of the plugin and instead would only affect developers
trying to develop on top of the old code.More details about these changes can be found on our GitHub repo.
Pinned the version of josepy to <2.0, since 2.0 introduced breaking changes
In anticipation of backwards incompatible changes, certbot-dns-cloudflare now requires less than version 2.20 of Cloudflare's python library.
More details about these changes can be found on our GitHub repo.
The Python source packages which we upload to PyPI are now also being uploaded to our releases on GitHub where we now also include a SHA256SUMS checks
More details about these changes can be found on our GitHub repo.
Support for Python 3.12 was added.
joinpath syntax to only use one addition per call, because the multiple inputs
version was causing mypy errors on Python 3.10.reconfigure verb actually use the staging server for the dry run to check the new
configuration.More details about these changes can be found on our GitHub repo.
Stop using the deprecated pkg_resources API included in setuptools.
pkg_resources API included in setuptools.More details about these changes can be found on our GitHub repo.
Fixed a bug introduced in version 2.7.0 that caused interactively entered webroot plugin values to not be saved for renewal.
More details about these changes can be found on our GitHub repo.
Fixed a bug where arguments with contained spaces weren't being handled correctly
More details about these changes can be found on our GitHub repo.
certbot-dns-ovh plugin now requires lexicon>=3.15.1 to ensure a consistent behavior with OVH APIs.
certbot-dns-ovh plugin now requires lexicon>=3.15.1 to ensure a consistent behavior with OVH APIs.More details about these changes can be found on our GitHub repo.
Fixed a bug that broke the DNS plugin for DNSimple that was introduced in version 2.7.0 of the plugin.
More details about these changes can be found on our GitHub repo.
Support for Python 3.7 was deprecated and will be removed in our next planned release.
certbot.util.LooseVersion class. See GH #9489.certbot.plugins.dns_common_lexicon.LexiconDNSAuthenticator to implement a DNS
authenticator plugin backed by Lexicon to communicate with the provider DNS API. This approach relies
heavily on conventions to reduce the implementation complexity of a new plugin.certbot.plugins.dns_test_common_lexicon.BaseLexiconDNSAuthenticatorTest to
help testing DNS plugins implemented on top of LexiconDNSAuthenticator.NamespaceConfig now tracks how its arguments were set via a dictionary, allowing us to remove a bunch
of global state previously needed to inspect whether a user set an argument or not.RENEWED_DOMAINS and FAILED_DOMAINS environment variables for consumption by post renewal hooks.LexiconClient base class and build_lexicon_config function in
certbot.plugins.dns_common_lexicon module in favor of LexiconDNSAuthenticator.BaseLexiconAuthenticatorTest and BaseLexiconClientTest test base classes of
certbot.plugins.dns_test_common_lexicon module in favor of BaseLexiconDNSAuthenticatorTest.certbot-dns-google to avoid usage of private DNS zones to create recordsMore details about these changes can be found on our GitHub repo.
certbot-dns-google no longer requires deprecated oauth2client library.
--dns-google-project optionally allows for specifying the project that the DNS zone(s) reside in,
which allows for Certbot usage in scenarios where the auth credentials reside in a different
project to the zone(s) that are being managed.Other annotated challenge object to allow plugins to support entirely novel challenges.allow-update-forwarding enabled
if the secondary did not also have the TSIG key within its config.dns_rfc2136_sign_query option in the credentials .ini file.--cert-name may no longer contain
filepath separators (i.e. / or \, depending on the platform).certbot-dns-google now loads credentials using the standard Application Default
Credentials strategy,
rather than explicitly requiring the Google Compute metadata server to be present if a service account
is not provided using --dns-google-credentials.--dns-google-credentials now supports additional types of file-based credential, such as
External Account Credentials created by Workload Identity
Federation. All file-based credentials implemented by the Google Auth library are supported.certbot-dns-google no longer requires deprecated oauth2client library.certbot.interfaces.{Installer,Authenticator} interface (e.g. certbot -i standalone
will now be ignored). See GH-9664.More details about these changes can be found on our GitHub repo.
--dns-route53-propagation-seconds is now deprecated. The Route53 plugin relies on the GetChange API to determine if a DNS update is complete. The flag…
acme.messages.OrderResource now supports being round-tripped
through JSONbegin_finalization
and poll_finalization methods, in addition to the existing
finalize_order method.--dns-route53-propagation-seconds is now deprecated. The Route53 plugin relies on the
GetChange API
to determine if a DNS update is complete. The flag has never had any effect and will be
removed in a future version of Certbot._internal/tests module.renew sometimes not preserving the key type of RSA certificates.
More details about these changes can be found on our GitHub repo.
We deprecated support for the update_symlinks command. Support will be removed in a following version of Certbot.
More details about these changes can be found on our GitHub repo.
certbot.configuration.NamespaceConfig.key_dir and .csr_dir are now deprecated.
reconfigure subcommand. See certbot help reconfigure for details.certbot show_account now displays the ACME Account Thumbprint./etc/letsencrypt/csr and /etc/letsencrypt/keys, respectively. These directories may be safely deleted./etc/letsencrypt/archive directory for each certificate lineage. Any prior certificates will be automatically deleted upon renewal. This number may be further lowered in future releases.
/etc/letsencrypt/live and never use /etc/letsencrypt/archive directly. See Where are my certificates? in the Certbot User Guide.certbot.configuration.NamespaceConfig.key_dir and .csr_dir are now deprecated.pytest to run tests.AttributeError: can't set attribute on ACME server errors in Python 3.11. See GH #9539.More details about these changes can be found on our GitHub repo.
Certbot will no longer respect very long challenge polling intervals, which may be suggested by some ACME servers. Certbot will continue to wait up to
Retry-After.More details about these changes can be found on our GitHub repo.
Interfaces which plugins register themselves as implementing without inheriting from them now show up in certbot plugins output.
certbot plugins output.IPluginFactory, IPlugin, IAuthenticator and IInstaller have been re-added to
certbot.interfaces.
AttributeError in Certbot v2.0.0.More details about these changes can be found on our GitHub repo.
Removed the deprecated certbot-dns-cloudxns plugin.
acme.challenges.HTTP01Response.simple_verify now accepts a timeout argument which defaults to 30 that causes the verification request to timeout after that many seconds.secp256r1 (P-256). It was previously RSA 2048-bit. Existing certificates are not affected.acme and Certbot no longer support versions of ACME from before the RFC 8555 standard.acme and Certbot no longer support the old urn:acme:error: ACME error prefix.certbot-dns-cloudxns plugin.--reuse-key set and a conflicting --key-type, --key-size or --elliptic-curve is requested on the CLI. Use --new-key to change the key while preserving --reuse-key.dist_name:plugin_name format on the CLI and in configuration files. Use the shorter plugin_name format.acme.client.Client, acme.client.ClientBase, acme.client.BackwardsCompatibleClientV2, acme.mixins, acme.client.DER_CONTENT_TYPE, acme.fields.Resource, acme.fields.resource, acme.magic_typing, acme.messages.OLD_ERROR_PREFIX, acme.messages.Directory.register, acme.messages.Authorization.resolved_combinations, acme.messages.Authorization.combinations have been removed.acme.messages.Directory now only supports lookups by the exact resource name string in the ACME directory (e.g. directory['newOrder']).source_address argument for acme.client.ClientNetwork.zope based interfaces in certbot.interfaces have been removed in favor of the abc based interfaces found in the same module.zope.certbot.util.get_strict_version.certbot.crypto_util.init_save_csr, certbot.crypto_util.init_save_key,
and certbot.compat.misc.execute_commandFileDisplay, NoninteractiveDisplay, SIDE_FRAME, input_with_timeout, separate_list_input, summarize_domain_list, HELP, and ESC from certbot.display.util have been removed.certbot.tests.util.patch_get_utility*. Plugins should now
patch certbot.display.util themselves in their tests or use
certbot.tests.util.patch_display_util as a temporary workaround.certbot.tests now uses unittest.mock instead of the 3rd party mock library.We plan to slowly roll out Certbot 2.0 to all of our snap users in the coming months. If you want to use the Certbot 2.0 snap now, please follow the instructions at https://community.letsencrypt.org/t/certbot-2-0-beta-call-for-testing/185945.
More details about these changes can be found on our GitHub repo.
DNS RFC2136 module now uses the TSIG key to check for an authoritative SOA record. Helps the use of split-horizon and multiple views in BIND9 using th
More details about these changes can be found on our GitHub repo.
If Certbot exits before setting up its usual log files, the temporary directory created to save logging information will begin with the name certbot-l
certbot-log- rather than a generic name. This should not be considered a stable aspect of Certbot and may change again in the future.--dns-cloudflare-credentials file as
well as the cloudflare.cfg configuration file of the Cloudflare library.More details about these changes can be found on our GitHub repo.
…and acme.fields.Resource are deprecated and will be removed in a future release.
acme.client.ClientBase, acme.messages.Authorization.resolved_combinations,
acme.messages.Authorization.combinations, acme.mixins, acme.fields.resource,
and acme.fields.Resource are deprecated and will be removed in a future release.acme.messages.OLD_ERROR_PREFIX (urn:acme:error:) is deprecated and support for
the old ACME error prefix in Certbot will be removed in the next major release of
Certbot.acme.messages.Directory.register is deprecated and will be removed in the next
major release of Certbot. Furthermore, .Directory will only support lookups
by the exact resource name string in the ACME directory (e.g. directory['newOrder']).certbot-dns-cloudxns plugin is now deprecated and will be removed in the
next major release of Certbot.source_address argument for acme.client.ClientNetwork is deprecated
and support for it will be removed in the next major release.More details about these changes can be found on our GitHub repo.
Updated Windows installer to be signed and trusted in Windows
--allow-subset-of-names will now additionally retry in cases where domains are rejected while creating or finalizing orders. This requires subproblem support from the ACME server.The show_account subcommand now uses the "newAccount" ACME endpoint to fetch the account
data, so it doesn't rely on the locally stored account URL. This fixes situations where Certbot
would use old ACMEv1 registration info with non-functional account URLs.
The generated Certificate Signing Requests are now generated as version 1 instead of version 3. This resolves situations in where strict enforcement of PKCS#10 meant that CSRs that were generated as version 3 were rejected.
More details about these changes can be found on our GitHub repo.
Updated Apache/NGINX TLS configs to document contents are based on ssl-config.mozilla.org
acme module and Certbot:
certificate field will only be processed if the order's status is valid.error field will only be processed if the order's status is invalid.More details about these changes can be found on our GitHub repo.
Added support for RFC8555 subproblems to our acme library.
F2871B4152AE13C49519111F447BF683AA3B26C3 was added as an
additional trusted key to sign our PyPI packagescertonly is run with an installer specified (e.g. --nginx),
certonly will now also run restart for that installerMore details about these changes can be found on our GitHub repo.
Added --new-key. When renewing or replacing a certificate that has --reuse-key set, it will force a new private key to be generated, one time.
Added --new-key. When renewing or replacing a certificate that has --reuse-key
set, it will force a new private key to be generated, one time.
As before, --reuse-key and --no-reuse-key can be used to enable and disable key
reuse.
--dns-ovh-propagation-seconds)
has been increased from 30 seconds to 120 seconds, based on user feedback.More details about these changes can be found on our GitHub repo.
Dropped 32 bit support for the Windows beta installer
run subcommand in combination with the --must-staple option.
If the installer does not support OCSP and the --must-staple option is used, Certbot
will raise an error and quit.More details about these changes can be found on our GitHub repo.
When the --debug-challenges option is used in combination with -v, Certbot now displays the challenge URLs (for http-01 challenges) or FQDNs (for dns-
--debug-challenges option is used in combination with -v, Certbot
now displays the challenge URLs (for http-01 challenges) or FQDNs (for
dns-01 challenges) and their expected return values.More details about these changes can be found on our GitHub repo.
We deprecated support for Python 3.6 in Certbot and its ACME library. Support for Python 3.6 will be removed in the next major release of Certbot.
show_account subcommand, which will fetch the account information
from the ACME server and show the account details (account URL and, if
applicable, email address or addresses)--key-path.
See GH #8569.More details about these changes can be found on our GitHub repo.
The function certbot.util.parse_loose_version was added to parse version strings in the same way as the now deprecated distutils.version.LooseVersion…
--issuance-timeout. This option specifies how long (in seconds) Certbot will wait
for the server to issue a certificate.web.config created by Certbot would sometimes
conflict with preexisting configurations (#9088).webroot plugin would crash when multiple domains
had the same webroot. This affected Certbot 1.21.0.More details about these changes can be found on our GitHub repo.
Certbot will generate a web.config file on Windows in the challenge path when the webroot plugin is used, if one does not exist. This web.config file
web.config file on Windows in the challenge path
when the webroot plugin is used, if one does not exist. This web.config file
lets IIS serve challenge files while they do not have an extension.More details about these changes can be found on our GitHub repo.
Added --no-reuse-key. This remains the default behavior, but the flag may be useful to unset the --reuse-key option on existing certificates.
--no-reuse-key. This remains the default behavior, but the flag may be
useful to unset the --reuse-key option on existing certificates.dnspython>=2.0. This has been relaxed to dnspython>=1.15.0.More details about these changes can be found on our GitHub repo.
Several attributes in certbot.display.util module are deprecated and will be removed in a future release of Certbot. Any import of these attributes wi…
certbot.display.util module are deprecated and will
be removed in a future release of Certbot. Any import of these attributes will
emit a warning to prepare the transition for developers.zope based interfaces in certbot.interfaces module are deprecated and will
be removed in a future release of Certbot. Any import of these interfaces will
emit a warning to prepare the transition for developers.chardet from our acme library. Except for when
downloading a certificate in an alternate format, our acme library now
assumes all server responses are UTF-8 encoded which is required by RFC 8555.Defined values in the Apache plugin to allow for = in the value.--quiet/-q.More details about these changes can be found on our GitHub repo.
New functions that Certbot plugins can use to interact with the user have been added to certbot.display.util. We plan to deprecate using IDisplay with…
certbot.display.util. We plan to deprecate using IDisplay
with zope in favor of these new functions in the future.Plugin, Authenticator and Installer classes are added to
certbot.interfaces module as alternatives to Certbot's current zope based
plugin interfaces. The API of these interfaces is identical, but they are
based on Python's abc module instead of zope. Certbot will continue to
detect plugins that implement either interface, but we plan to drop support
for zope based interfaces in a future version of Certbot.certbot.configuration.NamespaceConfig is added to the Certbot's
public API.acme: the .client.Client and .client.BackwardsCompatibleClientV2 classes
are now deprecated in favor of .client.ClientV2.certbot.tests.patch_get_utility* functions have been deprecated.
Plugins should now patch certbot.display.util themselves in their tests or
use certbot.tests.util.patch_display_util as a temporary workaround.Plugin and Installer in certbot.plugins.common module and
certbot.plugins.dns_common.DNSAuthenticator now implement Certbot's new
plugin interfaces. The Certbot plugins based on these classes are now
automatically detected as implementing these interfaces.chardet to our acme library so that it will be
used over charset_normalizer in newer versions of requests.More details about these changes can be found on our GitHub repo.
Add Void Linux overrides for certbot-apache.
ServerName. This should make it work more reliably with the
default Apache configuration in Debian-based environments.More details about these changes can be found on our GitHub repo.
…rely on the global Certbot config singleton, are deprecated and will be removed in a future release. Please use certbot.crypto_util.generate_key and c…
certbot.crypto_util.init_save_key and certbot.crypto_util.init_save_csr,
whose behaviors rely on the global Certbot config singleton, are deprecated and will
be removed in a future release. Please use certbot.crypto_util.generate_key and
certbot.crypto_util.generate_csr instead.More details about these changes can be found on our GitHub repo.
More details about these changes can be found on our GitHub repo.
More details about these changes can be found on our GitHub repo.
The module acme.magic_typing is deprecated and will be removed in a future release. Please use the built-in module typing instead.
acme.magic_typing is deprecated and will be removed in a future release.
Please use the built-in module typing instead.certbot certificates is being used
in combination with --cert-name or -d.More details about these changes can be found on our GitHub repo.
…which are related to certbot-auto, are deprecated and will be removed in a future release.
--os-packages-only, --no-self-upgrade, --no-bootstrap and --no-permissions-check,
which are related to certbot-auto, are deprecated and will be removed in a future release.security extras from requests
which was needed to support SNI in TLS requests when using old versions of
Python 2.six.--cert-name, it is no longer necessary to specify the --server
if the certificate was obtained from a non-default ACME server.More details about these changes can be found on our GitHub repo.
The --preferred-chain flag now only checks the Issuer Common Name of the topmost (closest to the root) certificate in the chain, instead of checking e
--preferred-chain flag now only checks the Issuer Common Name of the
topmost (closest to the root) certificate in the chain, instead of checking
every certificate in the chain.
See #8577.certbot/crypto_util.py causing an error upon attempting secp521r1 key generation
More details about these changes can be found on our GitHub repo.We deprecated support for Python 2 in Certbot and its ACME library. Support for Python 2 will be removed in the next planned release of Certbot.
pip install --user. This
was unintended and DNS plugins should be installed via snap instead.certbot-dns-google would sometimes crash with HTTP 409/412 errors when used with very large zones. See #6036.certbot-dns-google would sometimes crash with an HTTP 412 error if preexisting records had an unexpected TTL, i.e.: different than Certbot's default TTL for this plugin. See #8551.More details about these changes can be found on our GitHub repo.
Fixed a bug in certbot.util.add_deprecated_argument that caused the deprecated --manual-public-ip-logging-ok flag to crash Certbot in some scenarios.
certbot.util.add_deprecated_argument that caused the
deprecated --manual-public-ip-logging-ok flag to crash Certbot in some
scenarios.More details about these changes can be found on our GitHub repo.
Your coding agent can read these notes before it upgrades. Set up the MCP server →