# How can I disable TLS

**URL:** <https://community.letsencrypt.org/t/how-can-i-disable-tls/76491>\
**Category:** Client dev\
**Created:** [November 3, 2018, 3:21am UTC](https://community.letsencrypt.org/t/how-can-i-disable-tls/76491 "2018-11-03T03:21:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dxjones](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dxjones/32/27087_2.png) [@dxjones](https://community.letsencrypt.org/u/dxjones)\
**Post date:** [November 3, 2018, 3:21am UTC](https://community.letsencrypt.org/t/how-can-i-disable-tls/76491/1 "2018-11-03T03:21:13Z")

</div>

I am trying to get started on an ACME v2 client following example code from:

[https://github.com/eggsampler/acme](https://github.com/eggsampler/acme)

The provided “certbot” example works fine when it connects to the LetsEncrypt staging server.

But when I try to connect to Pebble, I get this failure (as expected):

**2018/11/02 23:11:49 Error connecting to acme directory: acme: error fetching response: Get [https://localhost:14000/dir:](https://localhost:14000/dir:) x509: certificate signed by unknown authority**

Pebble uses a self-signed certificate, so it is not signed by a recognized authority.

My question is: **What minimal surgery to eggsampler/acme is required to allow the TLS “InsecureSkipVerify” option to be enabled ??**

any tips appreciated,

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [November 3, 2018, 5:31am UTC](https://community.letsencrypt.org/t/how-can-i-disable-tls/76491/2 "2018-11-03T05:31:25Z")

</div>

Pebble always runs with TLS, unless you modify its source code not to.

So, the solution is not to disable TLS, but to disable certificate verification on the client side. You can find a precise example how to do that [here](https://github.com/eggsampler/acme/blob/797c6f352b291db17bae2787305e2edb6e67f9dc/utility_test.go#L282).

Basically,

```go
client, err := acme.NewClient("https://localhost:14000/dir", acme.WithInsecureSkipVerify())

```

Other “options” can be found in the godoc: [https://godoc.org/github.com/eggsampler/acme#OptionFunc](https://godoc.org/github.com/eggsampler/acme#OptionFunc)

---

<div class="post-metadata">

**Author:** ![dxjones](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dxjones/32/27087_2.png) [@dxjones](https://community.letsencrypt.org/u/dxjones)\
**Post date:** [November 3, 2018, 5:35am UTC](https://community.letsencrypt.org/t/how-can-i-disable-tls/76491/3 "2018-11-03T05:35:41Z")

</div>

Yes! This solves my problem. I just added that line to my code and got it working.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 3, 2018, 5:35am UTC](https://community.letsencrypt.org/t/how-can-i-disable-tls/76491/4 "2018-12-03T05:35:49Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
