# How update ACME client to use an alternative validation method (HTTP-01, DNS-01 or TLS-ALPN-01)

**URL:** <https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891>\
**Category:** Help\
**Created:** [January 18, 2019, 8:58am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891 "2019-01-18T08:58:54Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![giacomofarella](https://avatars.discourse-cdn.com/v4/letter/g/5f9b8f/32.png) [@giacomofarella](https://community.letsencrypt.org/u/giacomofarella)\
**Post date:** [January 18, 2019, 8:58am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/1 "2019-01-18T08:58:54Z")

</div>

I just got an email letting me know that TLS-SNI-01 domain validation is going away.  
How can i update my ACME client?

Thanks a lot  
Giacomo Farella

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: moon.miprenoto.eu

I ran this command:

It produced this output:

My web server is (include version): Apache 2.4.7

The operating system my web server runs on is (include version):

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don’t know):

I’m using a control panel to manage my site (no, or provide the name and version of the control panel):

---

<div class="post-metadata">

**Author:** ![lutzhorn](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lutzhorn/32/28978_2.png) [@lutzhorn](https://community.letsencrypt.org/u/lutzhorn)\
**Post date:** [January 18, 2019, 9:07am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/2 "2019-01-18T09:07:07Z")

</div>

Do you use certbot as the ACME client? How did you install it?

[https://certbot.eff.org/](https://certbot.eff.org/) should guide you to the installation process.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [January 18, 2019, 9:43am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/3 "2019-01-18T09:43:47Z")

</div>

Can you answer the other questions in your post? What ACME client are you using? What version is it now? How did you install it? What OS are you using?

---

<div class="post-metadata">

**Author:** ![giacomofarella](https://avatars.discourse-cdn.com/v4/letter/g/5f9b8f/32.png) [@giacomofarella](https://community.letsencrypt.org/u/giacomofarella)\
**Post date:** [January 18, 2019, 9:56am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/4 "2019-01-18T09:56:09Z")

</div>

ACME client: certbot  
Version: 0.11.0  
OS: ubuntu 14.04

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [January 18, 2019, 9:59am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/5 "2019-01-18T09:59:46Z")

</div>

How did you install it?

---

<div class="post-metadata">

**Author:** ![giacomofarella](https://avatars.discourse-cdn.com/v4/letter/g/5f9b8f/32.png) [@giacomofarella](https://community.letsencrypt.org/u/giacomofarella)\
**Post date:** [January 18, 2019, 10:00am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/6 "2019-01-18T10:00:51Z")

</div>

following the instructions [https://certbot.eff.org/lets-encrypt/ubuntutrusty-apache](https://certbot.eff.org/lets-encrypt/ubuntutrusty-apache)

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [January 18, 2019, 10:02am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/7 "2019-01-18T10:02:46Z")

</div>

The current version of python-certbot-apache for Trusty from the PPA [is 0.28](https://launchpad.net/~certbot/+archive/ubuntu/certbot/+packages?field.name_filter=certbot&field.status_filter=published&field.series_filter=trusty).

You should be able to upgrade (or try going through installation again).

You could also have duplicate versions of Certbot installed:

```
dpkg --list | grep -i certbot
```

---

<div class="post-metadata">

**Author:** ![giacomofarella](https://avatars.discourse-cdn.com/v4/letter/g/5f9b8f/32.png) [@giacomofarella](https://community.letsencrypt.org/u/giacomofarella)\
**Post date:** [January 18, 2019, 10:07am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/8 "2019-01-18T10:07:03Z")

</div>

is only necessary updating certbot to 0.28 version?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [January 18, 2019, 10:08am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/9 "2019-01-18T10:08:52Z")

</div>

0.28 is the first version that automatically chooses HTTP over TLS-SNI, yes. If you can upgrade to it, it is highly likely to be the only thing you need to do.

The only case where it may be insufficient is if you have some pre-configured preferred challenges already. This can be checked with:

```
grep -iR pref_challs /etc/letsencrypt/renewal/
```

---

<div class="post-metadata">

**Author:** ![giacomofarella](https://avatars.discourse-cdn.com/v4/letter/g/5f9b8f/32.png) [@giacomofarella](https://community.letsencrypt.org/u/giacomofarella)\
**Post date:** [January 18, 2019, 10:12am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/10 "2019-01-18T10:12:25Z")

</div>

Now i have upgraded certbot to 0.28 version. Do i need anything?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [January 18, 2019, 10:14am UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/11 "2019-01-18T10:14:12Z")

</div>

Yes, make sure your renewals are working:

```
certbot renew --dry-run

```

If that’s OK and there’s no warnings about TLS-SNI, you’re set.

---

<div class="post-metadata">

**Author:** ![neotruth](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/neotruth/32/29066_2.png) [@neotruth](https://community.letsencrypt.org/u/neotruth)\
**Post date:** [January 18, 2019, 5:46pm UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/12 "2019-01-18T17:46:42Z")

</div>

I received this email notification as well and wanted to share my findings.

I am on **Ubuntu 16.04 using Apache** web server. I first tried upgrading certbot from 0.21.0 to 0.28.0 (which, notably was "kept back" with a general `apt-get upgrade`, so I had to specify `certbot` to update only it and its dependencies) and the `--dry-run` output still showed warnings in red text about the TLS-SNI deprecation.

I realized **the Apache plugin had to be updated as well** to 0.28.0 and now the `--dry-run` completes without warnings and shows the http-01 challenge method is being used. Hope this helps.

```nohighlight
sudo apt-get install certbot python3-certbot-apache

```

From the [docs](https://certbot.eff.org/docs/challenges.html?highlight=challenges):

> Some plugins offer an _authenticator_ , meaning that they can satisfy challenges:
> 
> - Apache plugin: (TLS-SNI-01) Tries to edit your Apache configuration files to temporarily serve a Certbot-generated certificate for a specified name. Use the Apache plugin when you’re running Certbot on a web server with Apache listening on port 443.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [February 17, 2019, 5:46pm UTC](https://community.letsencrypt.org/t/how-update-acme-client-to-use-an-alternative-validation-method-http-01-dns-01-or-tls-alpn-01/82891/13 "2019-02-17T17:46:46Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
