# Dry-run uses ACME-V02, renewal uses ACME-V01

**URL:** <https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994>\
**Category:** Issuance Tech\
**Created:** [March 10, 2020, 1:59pm UTC](https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994 "2020-03-10T13:59:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mkooring](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mkooring](https://community.letsencrypt.org/u/mkooring)\
**Post date:** [March 10, 2020, 2:00pm UTC](https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994/1 "2020-03-10T14:00:00Z")

</div>

I am on Ubuntu 16.04  
certbot version= 0.31.0

I got an email from Letsencrypt telling me to upgrade from ACMEv1 to ACMEv2.

It sais

* * *

According to our records, the software client you’re using to get Let’s  
Encrypt TLS/SSL certificates issued or renewed at least one HTTPS certificate  
in the past two weeks using the ACMEv1 protocol. Here are the details of one  
recent ACMEv1 request from each of your account(s):

Client IP address: x.x.x.x

User agent: CertbotACMEClient/0.31.0 (certbot; Ubuntu 16.04.6 LTS) Authenticator/apache Installer/apache (renew; flags: n) Py/3.5.2

Hostname(s): “xxxxxxxxxxxxx”

Request time: 2020-03-03 03:17:38 UTC

* * *

Checking the log confirm this. here is a line from the log:

* * *

2020-03-03 04:17:30,472:DEBUG:acme.client:Sending GET request to [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory).

* * *

I have tried to upgrade and I thought I had been success because when I do a dry-run it sais:

* * *

Cert not due for renewal, but simulating renewal for dry run  
Plugins selected: Authenticator apache, Installer apache  
Starting new HTTPS connection (1): [acme-staging-v02.api.letsencrypt.org](http://acme-staging-v02.api.letsencrypt.org)  
Renewing an existing certificate

* * *

The question is, why is the dry run using v2 while the normal renewal uses v1.

The renewal uses the systemd timers and my certbot.service files looks like this:

* * *

[Unit]  
Description=Certbot  
Documentation=file:///usr/share/doc/python-certbot-doc/html/index.html  
Documentation=https://letsencrypt.readthedocs.io/en/latest/  
[Service]  
Type=oneshot  
ExecStart=/usr/bin/certbot -q renew  
PrivateTmp=true

* * *

I have noticed that my config file in /etc/letsencrypt/xxxxxx.conf has a hard reference to v1:  
server = [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory)

Should I change or remove this?

I am lost, please help? Why is the dry-run result different from the renewal?  
How do I set the renewal to use acmev2?

Please help.

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 10, 2020, 2:04pm UTC](https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994/2 "2020-03-10T14:04:07Z")

</div>

you can set it on the commandline with `certbot renew --server` and certbot should edit its conf accordingly.

> [@How to update to ACME v2 with old certbot installation](https://community.letsencrypt.org/t/how-to-update-to-acme-v2-with-old-certbot-installation/112065/2):
>
> H…

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [March 10, 2020, 2:17pm UTC](https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994/3 "2020-03-10T14:17:35Z")

</div>

If you run “`apt list --upgradeable`”, are all of your packages up-to-date?

If you run “`grep ^server /etc/letsencrypt/cli.ini /etc/letsencrypt/renewal/*.conf`”, are any of the configuration files forcing the use of the ACMEv1 API?

---

<div class="post-metadata">

**Author:** ![mkooring](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mkooring](https://community.letsencrypt.org/u/mkooring)\
**Post date:** [March 10, 2020, 2:19pm UTC](https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994/4 "2020-03-10T14:19:19Z")

</div>

I ran:  
sudo certbot -vvv renew --server [https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory)

And the output looks good.

But when I check my conf files, the hard reference to ACME-V01 is still there:

* * *

[renewalparams]  
installer = apache  
authenticator = apache  
account = \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
**server = [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory)**  
standalone\_supported\_challenges = “tls-sni-01,http-01”  
apache\_vhost\_root = /etc/apache2/sites-available  
apache\_ctl = None

* * *

What should I do?

Adjust the certbot.service file to include the --server option and hardcode it that way. (does not seem the right thing to do)

---

<div class="post-metadata">

**Author:** ![9peppe](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/9peppe/32/31596_2.png) [@9peppe](https://community.letsencrypt.org/u/9peppe)\
**Post date:** [March 10, 2020, 2:23pm UTC](https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994/5 "2020-03-10T14:23:53Z")

</div>

backup the configuration file and edit it, it should be safe to do so: [https://certbot.eff.org/docs/using.html#configuration-file](https://certbot.eff.org/docs/using.html#configuration-file)

---

<div class="post-metadata">

**Author:** ![mkooring](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mkooring](https://community.letsencrypt.org/u/mkooring)\
**Post date:** [March 10, 2020, 2:25pm UTC](https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994/6 "2020-03-10T14:25:03Z")

</div>

I guess not all of them are update to:  
I ran: apt list --upgradeable

Listing… Done  
libdrm2/xenial-updates 2.4.91-2~16.04.1 amd64 [upgradable from: 2.4.76-1~ubuntu16.04.1]  
python-cryptography/xenial 1.9-1+ubuntu16.04.1+certbot+2 amd64 [upgradable from: 1.2.3-1ubuntu0.2]  
python-openssl/xenial,xenial 17.3.0-1~0+ubuntu16.04.1+certbot+1 all [upgradable from: 0.15.1-2ubuntu0.2]  
python-requests/xenial,xenial 2.18.1-1+ubuntu16.04.1+certbot+1 all [upgradable from: 2.9.1-3ubuntu0.1]  
python-urllib3/xenial,xenial 1.21.1-1+ubuntu16.04.1+certbot+1 all [upgradable from: 1.13.1-2ubuntu0.16.04.3]  
python3-requests/xenial,xenial 2.18.1-1+ubuntu16.04.1+certbot+1 all [upgradable from: 2.9.1-3ubuntu0.1]  
python3-urllib3/xenial,xenial 1.21.1-1+ubuntu16.04.1+certbot+1 all [upgradable from: 1.13.1-2ubuntu0.16.04.3]  
ubuntu-minimal/xenial-updates 1.361.4 amd64 [upgradable from: 1.361.1]

How to get these upgraded?  
When I do a normal upgrade (sudo apt-get upgrade), it sais  
The following packages have been kept back:  
libdrm2 python-cryptography python-openssl python-requests python-urllib3 python3-requests python3-urllib3 ubuntu-minimal

And yes, my config file are forcing ACMEv1, as menioned they have a server setting:  
server = [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory)

Should I change that? Should I remove that?

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [March 10, 2020, 2:33pm UTC](https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994/7 "2020-03-10T14:33:43Z")

</div>

> [@mkooring](#):
>
> And yes, my config file are forcing ACMEv1, as menioned they have a server setting:  
> server = [https://acme-v01.api.letsencrypt.org/directory](https://acme-v01.api.letsencrypt.org/directory)
> 
> Should I change that? Should I remove that?

Changing it -- change the `1` to `2` -- would work.

I'm 99% sure deleting it would also work; Certbot should use the (correct) default if it's unspecified.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [April 9, 2020, 2:33pm UTC](https://community.letsencrypt.org/t/dry-run-uses-acme-v02-renewal-uses-acme-v01/115994/8 "2020-04-09T14:33:55Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
