P
P
poisons2017-12-20 21:52:26
ISPmanager
poisons, 2017-12-20 21:52:26

letsencrypt stopped working in ispmanager, how to fix it?

Given
1. Debian 8
2. ispmanager 5.124.0
The problem is that automatic certificate renewal stopped working. in the logs

return code:400
Details:Provided agreement URL [ https://letsencrypt.org/documents/LE-SA-v1.1.1-Aug... does not match current agreement URL [ https://letsencrypt.org/documents/LE -SA-v1.2-Novem...

Googling the Internet, it became clear that there were changes on the part of the CA and the mechanism for issuing certificates. Updated acme.sh, didn't help, still the same error in the logs. For the sake of interest, I decided to crack all over the FS in search of an occurrence of the string LE-SA-v1.1.1-August-1-2016.pdf and caught
Binary file /usr/local/mgr5/lib/letsencrypt_lite.so matches
Binary file /usr/local/ mgr5/etc/ispmgr.db-wal matches
/usr/local/mgr5/etc/scripts/acmesh/acme.sh.old:DEFAULT_AGREEMENT=" https://letsencrypt.org/documents/LE-SA-v1.1.1- Aug... "
In the old acme.sh I tried to change the url to a new one, it does not help. There is a suspicion that these bad people put the url directly into the binaries, I'm not ready to pick the binaries yet.
This has been fixed in new versions of ispmanager, but the subscription has expired and there are no plans to buy it.
Actually the question
is How to win with little bloodshed?

Answer the question

In order to leave comments, you need to log in

3 answer(s)
V
Vladimir Mukovoz, 2017-12-20
@poisons

Get the certificate by hand and put it on the crowns to reissue it.

D
dronn23, 2019-07-22
@dronn23

If anyone else is suffering from this problem, then I have a solution.
Download /usr/local/mgr5/lib/letsencrypt_lite.so (Attention! Save this file in case something goes wrong)
Open it in notepad++ (UTF-8 without BOM required!)
Change " https://letsencrypt .org/documents/LE-SA-v1.1.1-Aug... " to " https://letsencrypt.org/documents/LE-SA-v1.2-Novem... "
However, in the new single character reference more, so we remove one "NUL" right after .pdf
. Upload the file back to the server and reload.

V
vrn00b, 2018-08-04
@vrn00b

in the letsencrypt_lite.so file, replace the line with notepad++ and restart the server

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question