# Certbot upgrade to support ACMEv2

**URL:** <https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720>\
**Category:** Help\
**Created:** [January 16, 2020, 1:24am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720 "2020-01-16T01:24:16Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 1:24am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/1 "2020-01-16T01:24:16Z")

</div>

I received the ACMEv1 deprecation email and need to revisit upgrading my certbot client, reconfiguring an existing working configuration to utilize ACMEv2, and test the operation ( without breakage :-).  
  
I am using a GCE instance Debian 4.9.110-3+deb9u6 and certbot --version 0.28.0 after apt-get update from version 0.10.2 that has been successfully working since at least 2018. Github for certbot lists versions as new as 1.1.0 so I am not sure which is the correct one for least problems.  
  
Does anyone have current instruction steps, links to concise documentation or other information that can help me accomplish this upgrade?   
 I hope this will also help others who received the “dreaded depreciation” email.  
  
Adding this link mentioning using Let’s Encrypt’s new ACMEv2 server:  
  
“For example, if you would like to use Let’s Encrypt’s new ACMEv2 server, you would add `--server https://acme-v02.api.letsencrypt.org/directory ` to the command line.”  
  
But I don’t see where to permanently set the configuration.

> **[User Guide — Certbot 1.1.0.dev0 documentation](https://certbot.eff.org/docs/using.html?highlight=acmev2#changing-the-acme-server)**
>
> Automatically enable HTTPS on your website with EFF's Certbot, deploying Let's Encrypt certificates.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 16, 2020, 3:15am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/2 "2020-01-16T03:15:27Z")

</div>

> [@mojoa](#):
>
> I don’t see where to permanently set the configuration.

Although I don't understand why you would need to specify the acmev2 server, you can make such changes (globally) in the config file: [User Guide — Certbot 2.7.0.dev0 documentation](https://certbot.eff.org/docs/using.html?highlight=acmev2#config-file)

As for the decision between 0.28.0 and 1.1.0 …  
I would stick with the apt package files until they no longer work.  
And if/when that happens, I would probably try upgrading the O/S first.  
If that is NOT an option then ask your question here ("Which version should I go to?").  
Unless that is why you asked it now...  
Does your 0.28.0 version still work?  
What does the "dreaded deprecation" email say exactly (regarding your 0.28.0 version)?

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [January 16, 2020, 3:20am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/3 "2020-01-16T03:20:34Z")

</div>

> [@mojoa](#):
>
> Adding this link mentioning using Let’s Encrypt’s new ACMEv2 server:
> 
> “For example, if you would like to use Let’s Encrypt’s new ACMEv2 server, you would add `--server https://acme-v02.api.letsencrypt.org/directory ` to the command line.”

The documentation is out-of-date 😓 -- recent versions of Certbot use the ACMEv2 server by default. You don't have to configure anything.

There were a few releases of Certbot that had early ACMEv2 support but didn't prefer it by default. Some or all of those versions also had bugs that mean you have to upgrade anyway.

Edit:

> [@mojoa](#):
>
> Debian 4.9.110-3+deb9u6

That's a Linux kernel version, not a Debian version -- though the "deb9" part probably means it's Debian 9. Can you run something like "`lsb_release -a`" to confirm what version of Debian you're using?

Edit: [I filed a quick bug report about the docs.](https://github.com/certbot/certbot/issues/7686)

---

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 3:29am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/4 "2020-01-16T03:29:02Z")

</div>

This is a GCE instance.  
lsb\_release -a  
No LSB modules are available.  
Distributor ID: Debian  
Description: Debian GNU/Linux 9.11 (stretch)  
Release: 9.11  
Codename: stretch  
2020-01-15 18:17:02,273:DEBUG:certbot.renewal:no renewal failures  
2020-01-16 03:18:54,779:DEBUG:certbot.main:certbot version: 0.28.0

I have an entry in crontab which checks for renewal.  
Is there an entry which verifies I am configured properly to hit the ACMEv2 server thus complying with the depreciation email 🙂

---

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 3:36am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/5 "2020-01-16T03:36:36Z")

</div>

Linking the email discussion:

> [@ACMEv1 deprecation e-mails](https://community.letsencrypt.org/t/acmev1-deprecation-e-mails/110607):
>
> F…

I prefer to use whatever version of certbot is supplied in the GCE distribution if possible. As long as they are reasonably up to date..

I am not sure how to tell if certbot is working. Not sure of the command to test.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 16, 2020, 3:45am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/6 "2020-01-16T03:45:40Z")

</div>

> [@mojoa](#):
>
> I am not sure how to tell if certbot is working. Not sure of the command to test.

See: [User Guide — Certbot 2.7.0.dev0 documentation](https://certbot.eff.org/docs/using.html#certbot-command-line-options)  
`--dry-run Test "renew" or "certonly" without saving any certificates to disk`

---

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 3:48am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/7 "2020-01-16T03:48:11Z")

</div>

Editing the config files comes with a warning 🙂

Warning

Modifying any files in /etc/letsencrypt can damage them so Certbot can no longer properly manage its certificates, and we do not recommend doing so.

> **[User Guide — Certbot 1.1.0.dev0 documentation](https://certbot.eff.org/docs/using.html?highlight=acmev2#id23)**
>
> Automatically enable HTTPS on your website with EFF's Certbot, deploying Let's Encrypt certificates.

---

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 3:59am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/8 "2020-01-16T03:59:18Z")

</div>

Looks like it is hitting v2 server.

```auto
https://acme-staging-v02.api.letsencrypt.org:443 "GET /acme/authz-v3/33098456 HTTP/1.1" 405 103
Received response:
HTTP 405

```

Looks like fullchain.pem (failure)

What needs to happen to renew my pem files?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 16, 2020, 4:04am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/9 "2020-01-16T04:04:55Z")

</div>

First: Stick with `--dry-run` until you get it all figured out or you may hit some limits.  
Second: Provide as much detail on the command line used and the error message received.  
[see tail of `/var/log/letsencrypt/letsencrypt.log` file - or wherever the LE log file may reside]

[edit]  
Understand `--dry-run` will do absolutely nothing:

- nothing when it passes
- nothing when it fails

The only good you can get from it is found in the logs (and it shouldn’t trip any limits)

---

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 4:12am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/10 "2020-01-16T04:12:03Z")

</div>

OK…  
root# /usr/bin/certbot --dry-run -v  
Tons of data:  
One error shown:  
Link: [https://acme-staging-v02.api.letsencrypt.org/directory](https://acme-staging-v02.api.letsencrypt.org/directory);rel=“index”

{  
“type”: “urn:ietf:params:acme:error:malformed”,  
“detail”: “Method not allowed”,  
“status”: 405  
}  
Exiting abnormally:  
Traceback (most recent call last):  
File “/usr/bin/certbot”, line 11, in   
load\_entry\_point(‘certbot==0.28.0’, ‘console\_scripts’, ‘certbot’)()  
File “/usr/lib/python3/dist-packages/certbot/main.py”, line 1340, in main  
return config.func(config, plugins)  
File “/usr/lib/python3/dist-packages/certbot/main.py”, line 1247, in renew  
renewal.handle\_renewal\_request(config)  
File “/usr/lib/python3/dist-packages/certbot/renewal.py”, line 455, in handle\_renewal\_request  
len(renew\_failures), len(parse\_failures)))  
certbot.errors.Error: 2 renew failure(s), 0 parse failure(s)  
2 renew failure(s), 0 parse failure(s)

acme.messages.Error: urn:ietf:params:acme:error:malformed :: The request message was malformed :: Method not allowed

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 16, 2020, 4:18am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/11 "2020-01-16T04:18:56Z")

</div>

Let me invite some to have a look, that may be more familiar with this error:  
@schoen @_az

In the meantime, maybe delete the LE log file (or move it) and create a new one.  
Then post that new one here (or a link to it).

---

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 4:21am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/12 "2020-01-16T04:21:04Z")

</div>

Thank You..

Here is a post which mentions this and also mentions staging server and dry run.

> [@Problem with renew certificates - The request message was malformed :: Method not allowed](https://community.letsencrypt.org/t/problem-with-renew-certificates-the-request-message-was-malformed-method-not-allowed/107889/4):
>
> I…

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 16, 2020, 4:28am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/13 "2020-01-16T04:28:05Z")

</div>

Following that thread, can you post all the package files and their version installed?

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [January 16, 2020, 4:28am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/14 "2020-01-16T04:28:48Z")

</div>

You need to upgrade Certbot – or, more precisely, one of its component libraries.

I think the current version in stretch-updates works.

Are all of your packages up-to-date?

What does “`dpkg -l python3-acme`” show?

What does “`apt list --upgradeable`” show?

---

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 4:32am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/15 "2020-01-16T04:32:23Z")

</div>

> [@mnordhoff](#):
>
> `dpkg -l python3-acme` ” show

root@instance-1:/etc/letsencrypt# apt list --upgradeable  
Listing... Done  
linux-image-amd64/oldstable 4.9+80+deb9u9 amd64 [upgradable from: 4.9+80+deb9u6]  
python-acme/oldstable 0.28.0-1~deb9u1 all [upgradable from: 0.10.2-1]  
root@instance-1:/etc/letsencrypt# dpkg -l python3-acme” show  
dpkg-query: no packages found matching python3-acme”  
dpkg-query: no packages found matching show  
root@instance-1:/etc/letsencrypt#

I did apt-get update earlier to get to version 28. Do I also need to do a apt-get upgrade as well?

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [January 16, 2020, 4:43am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/16 "2020-01-16T04:43:57Z")

</div>

> [@mojoa](#):
>
> root@instance-1:/etc/letsencrypt# apt list --upgradeable  
> Listing… Done  
> linux-image-amd64/oldstable 4.9+80+deb9u9 amd64 [upgradable from: 4.9+80+deb9u6]  
> python-acme/oldstable 0.28.0-1~deb9u1 all [upgradable from: 0.10.2-1]

So `python-acme` is definitely out-of-date. But the current `certbot` package shouldn't be using it. Older versions might have.

(`python-`\* packages are for Python 2 and `python3-`\* packages are for Python 3. Recent Certbot packages run with Python 3. Older ones probably use Python 2.)

> [@mojoa](#):
>
> root@instance-1:/etc/letsencrypt# dpkg -l python3-acme” show  
> dpkg-query: no packages found matching python3-acme”  
> dpkg-query: no packages found matching show

Run it again without the `” show` at the end. Just:

`dpkg -l python3-acme`

> [@mojoa](#):
>
> I did apt-get update earlier to get to version 28. Do I also need to do a apt-get upgrade as well?

`apt-get update` doesn't upgrade your packages. It just downloads the new list of packages.

---

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 4:45am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/17 "2020-01-16T04:45:56Z")

</div>

> [@mnordhoff](#):
>
> dpkg -l python3-acme

```nohighlight
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name Version Architecture Description
+++-===========================================================-==================================-==================================-============================================================================================================================
ii python3-acme 0.28.0-1~deb9u1 all ACME protocol library for Python 3
root@instance-1:/etc/letsencrypt#

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [January 16, 2020, 4:46am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/18 "2020-01-16T04:46:32Z")

</div>

Bingo!

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [January 16, 2020, 4:47am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/19 "2020-01-16T04:47:30Z")

</div>

> [@mojoa](#):
>
> 0.28.0-1~deb9u1

You need to upgrade to the current version, 0.28.0-1~deb9u2, to resolve the "Method not allowed" issue. (I think.)

It's in stretch-updates. If the repository is enabled, running `apt update` and `apt upgrade` should take care of it.

---

<div class="post-metadata">

**Author:** ![mojoa](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@mojoa](https://community.letsencrypt.org/u/mojoa)\
**Post date:** [January 16, 2020, 4:59am UTC](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720/20 "2020-01-16T04:59:25Z")

</div>

Unfortunately apt update and apt upgrade did not solve the issue for me. The – dry-run still errors the same. There was some mention that this only affects the dry-run and staging server, but live updates should work. Is that true?

I was trying to keep this GCE instance totally pristine, only using packages from configured repos. Is that an impossible thing to try to do? certbot has been working fine since 2017 …

[Next page](https://community.letsencrypt.org/t/certbot-upgrade-to-support-acmev2/110720.md?page=2)
