Author Topic: Warning e-mail from Let's Encrypt  (Read 2046 times)

Offline petr.necas

  • Sr. Member
  • ****
  • Posts: 393
  • Country: cz
  • Karma: +8/-0
    • View Profile
Warning e-mail from Let's Encrypt
« on: March 29, 2020, 04:30:32 PM »
I've got following e-mail from Let's Encrypt. Do you know how to switch the MSL server to start using ACMEv2?


Hi,

According to our records, the software client you're using to get Let's Encrypt TLS/SSL certificates issued or renewed at least one HTTPS certificate in the past two weeks using the ACMEv1 protocol. Here are the details of one recent ACMEv1 request from each of your account(s):

Client IP address:  xxx.xxx.xxx.xxx

User agent:  curl/7.19.7 (x86_64-redhat-linux-gnu) libcurl/7.19.7 NSS/3.27.1 zlib/1.2.3 libidn/1.18 libssh2/1.4.2

Hostname(s):  "mbg.mitel.xxxxxxxxxx.eu","mbg.mitel.xxxxxxxxxx.eu","micollab.mitel.xxxxxxxxxx.eu","mcd.mitel.xxxxxxxxxx.eu"

Request time:  2020-03-08 03:27:25 UTC

Beginning June 1, 2020, we will stop allowing new domains to validate using the ACMEv1 protocol. You should upgrade to an ACMEv2 compatible client before then, or certificate issuance will fail. For most people, simply upgrading to the latest version of your existing client will suffice. You can view the client list at: https://letsencrypt.org/docs/client-options/

If you're unsure how your certificate is managed, get in touch with the person who installed the certificate for you. If you don't know who to contact, please view the help section in our community forum at https://community.letsencrypt.org/c/help and use the search bar to check if there's an existing solution for your question. If there isn't, please create a new topic and fill out the help template.

ACMEv1 API deprecation details can be found in our community forum:
https://community.letsencrypt.org/t/end-of-life-plan-for-acmev1

As a reminder: In the future, Let's Encrypt will be performing multiple domain validation requests for each domain name when you issue a certificate.
While you're working on migrating to ACMEv2, please check that your system configuration will not block validation requests made by new Let's Encrypt IP addresses, or block multiple matching requests. Per our FAQ (https://letsencrypt.org/docs/faq/), we don't publish a list of IP addresses we use to validate, and this list may change at any time.

To receive more frequent updates, subscribe to our API Announcements:
https://community.letsencrypt.org/t/about-the-api-announcements-category

Thank you for joining us on our mission to create a more secure and privacy- respecting Web!

All the best,

Let's Encrypt


Offline johnp

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 2183
  • Country: us
  • Karma: +66/-0
    • View Profile
Re: Warning e-mail from Let's Encrypt
« Reply #1 on: March 29, 2020, 09:58:34 PM »
There is a knowledgebase article on updating to v2

Offline petr.necas

  • Sr. Member
  • ****
  • Posts: 393
  • Country: cz
  • Karma: +8/-0
    • View Profile
Re: Warning e-mail from Let's Encrypt
« Reply #2 on: March 30, 2020, 04:03:19 AM »
I found article "Let's Encrypt ACMEv2 support for MSL 11.0.53+"....Is this all what I need to do? When clicked the Get Certificate button I got "Successfully deployed certificate." before and after I applied the patch.

Resolution
Upload attached file using WinSCP (or similar) to the MSL server /tmp directory

SSH to the server and login as root.
run the command
rpm -Uvh /tmp/mitel-msl-webservercert-1.12.37-02.noarch.rpm

Offline jmiker

  • New Member
  • *
  • Posts: 4
  • Country: us
  • Karma: +0/-0
    • View Profile
Re: Warning e-mail from Let's Encrypt
« Reply #3 on: May 18, 2020, 05:03:30 PM »
There is a knowledgebase article on updating to v2

Any chance you could lay your hands on it? I'm not seeing any search results here, in the Mitel.com Document Center, MiContact KB, or the OneView site.

Or if you could point me in the right direction, I certainly don't mind digging.

Thanks!

Offline johnp

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 2183
  • Country: us
  • Karma: +66/-0
    • View Profile
Re: Warning e-mail from Let's Encrypt
« Reply #4 on: May 19, 2020, 06:10:31 PM »
It is in the Mitel Knowledgebase, a patch is available, and I did it on a server with an earlier version than that which was documented. Might not work for you though.
« Last Edit: May 19, 2020, 06:13:31 PM by johnp »


 

Sitemap 1 2 3 4 5 6 7 8 9 10