Thanks for investigating, I did another run and captured the entire certificate chain as received from the staging endpoint. BouncyCastle reads the serial as 21790042814121155191743235894085329638597059
.
Then I GET
to https://acme-staging-v02.api.letsencrypt.org/get/draft-ietf-acme-ari-00/renewalInfo/MGgwDQYJYIZIAWUDBAIBBQAEINbwv9Ii7lJ7Rl4MK_UC8owq_M2InTeCZYXsMrnbPuPwBCDNzUtT3QwFEFhoaK3_FfGJEtnTw644tq24sfDn3seIAQITAPojLjqFA3zKfrlqpLFiaishww
, which succeeds and suggests renewal between 2023-05-26 and 2023-05-28.
Then I POST
to https://acme-staging-v02.api.letsencrypt.org/get/draft-ietf-acme-ari-00/renewalInfo/
with this as payload:
{"protected":"eyJhbGciOiJFUzI1NiIsInVybCI6Imh0dHBzOi8vYWNtZS1zdGFnaW5nLXYwMi5hcGkubGV0c2VuY3J5cHQub3JnL2dldC9kcmFmdC1pZXRmLWFjbWUtYXJpLTAwL3JlbmV3YWxJbmZvLyIsIm5vbmNlIjoiQTI3MkExX1JnbHl0T25DWkhxSFpMNkRtNGs0d254aEhQdlBzSjM1eWZQckViREkiLCJraWQiOiJodHRwczovL2FjbWUtc3RhZ2luZy12MDIuYXBpLmxldHNlbmNyeXB0Lm9yZy9hY21lL2FjY3QvOTM4NjY2MTQifQ","payload":"eyJjZXJ0SUQiOiJNR2d3RFFZSllJWklBV1VEQkFJQkJRQUVJTmJ3djlJaTdsSjdSbDRNS19VQzhvd3FfTTJJblRlQ1pZWHNNcm5iUHVQd0JDRE56VXRUM1F3RkVGaG9hSzNfRmZHSkV0blR3NjQ0dHEyNHNmRG4zc2VJQVFJVEFQb2pManFGQTN6S2ZybHFwTEZpYWlzaHd3IiwicmVwbGFjZWQiOnRydWV9","signature":"bW1SR6uuG2dysdnLy6F_0MMim_sy4iGzDXG1dWWZUXipNcb6c7WVwztbp4oJlWs3NpX9nu17f5XB5B0_aI1zKA"}
Which boils down to:
{"certID":"MGgwDQYJYIZIAWUDBAIBBQAEINbwv9Ii7lJ7Rl4MK_UC8owq_M2InTeCZYXsMrnbPuPwBCDNzUtT3QwFEFhoaK3_FfGJEtnTw644tq24sfDn3seIAQITAPojLjqFA3zKfrlqpLFiaishww","replaced":true}
(note that the certID is identical between the POST payload and the GET url)
And the response looks like
{
"type": "urn:ietf:params:acme:error:malformed",
"detail": "Certificate not found",
"status": 404
}
Here is the full certificate chain for the certificate that I got for this run, straight from Boulder:
-----BEGIN CERTIFICATE-----
MIIF7TCCBNWgAwIBAgITAPojLjqFA3zKfrlqpLFiaishwzANBgkqhkiG9w0BAQsF
ADBZMQswCQYDVQQGEwJVUzEgMB4GA1UEChMXKFNUQUdJTkcpIExldCdzIEVuY3J5
cHQxKDAmBgNVBAMTHyhTVEFHSU5HKSBBcnRpZmljaWFsIEFwcmljb3QgUjMwHhcN
MjMwMzI4MTYyODU1WhcNMjMwNjI2MTYyODU0WjAmMSQwIgYDVQQDExthbm90aGVy
LndvdXRlci50aW51cy5vbmxpbmUwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGK
AoIBgQCCwZpKcBoVH86lyVvdUZGdL/mllPSU/OLvkCrp6w4Y8owF0tVttRBclhJK
nMvSoezOhRllnPKkfi8DjFbasMQqqwys/GLPXFBzvGsfLeZTn2/CheBR7lkjsWXg
ANhRz14qpMbo8163/+Yo/m+Zv59lec7dQ3+2GKIPjQA/mB7mS6ZNo3/zZXv8S3E3
EIXiUD4j3rhYd4uuD09B/EnI7fcOMtGM6Zn6jgDehr5wBBtUs/Lk7D/48OPqg0sL
7sZFr3ZWitH49lBMeLdJKQv1u5VKsDLrWRqr4i+d4g9acVv8AAtAnAOPiwoQ/ScZ
bMxhqKHyOIwtvMIlMKlrYqjqVmr03Z7AMBD2E+S5jwiFoceUFhTHeGFeyz+SI/4l
7hOD/OOfwpqBVO2Sj68oM3CayeXpNjgrL1ccKgNjjEHIjazDs7WiI6t5ZHiaLScV
GcRMW/NHmzoSNNMPda8s6VI6iUUq9QxDOqU+Pb89j7UZ2g1Xn9m5hOKldewG7Qoo
fwLbQKMCAwEAAaOCAl8wggJbMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggr
BgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUkJ+oLUq1
ZdSb5dkEqd/sbQnmJZ8wHwYDVR0jBBgwFoAU3nJ6SN8xw6ZQ35+FI99XN0tdLmUw
XQYIKwYBBQUHAQEEUTBPMCUGCCsGAQUFBzABhhlodHRwOi8vc3RnLXIzLm8ubGVu
Y3Iub3JnMCYGCCsGAQUFBzAChhpodHRwOi8vc3RnLXIzLmkubGVuY3Iub3JnLzAm
BgNVHREEHzAdghthbm90aGVyLndvdXRlci50aW51cy5vbmxpbmUwTAYDVR0gBEUw
QzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAmBggrBgEFBQcCARYaaHR0cDov
L2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEFBgorBgEEAdZ5AgQCBIH2BIHzAPEAdwDB
gyQL8aRQx2+7AHJp3Kw74ipIBdTb4Elmw8irxEewDAAAAYcpRAB5AAAEAwBIMEYC
IQCgO9EJzLrRnl6Qt/rkyQPdmpV/agl5Md4v2IKELXF8bAIhAOc9kwUHW6lQSH2J
ZIhPapaZk0jeLTr6px5WeuYEE62wAHYAsMyD5aX5fWuvfAnMKEkEhyrH6IsTLGNQ
t8b9JuFsbHcAAAGHKUQAcQAABAMARzBFAiEAx1+pZTYfSewsY0pj6mnOCrCsFHSk
X/ZdaIJKa89oCVUCIGV1D8TftEVrdVh2Z99D+pQDIcakkMkPJwfjfOuq8HgVMA0G
CSqGSIb3DQEBCwUAA4IBAQBg71Xt0MaLcwALeTgUDJ14pxHDstuMdpKPqNSVvEZN
26Ocx7cbE+klxUIaHh5UO/UwgRwPBshbgHGtbpKy3UG8qdChGmNHg8zhwbOpRQcw
G2NhNWQlFVGNeedKH6YZQeS+Edwk5rg4SEKTK2cDkBf5al8xTWyZYyPfoQnDlzvi
2/9/jh71qathgjsX07EOjtvpDg73tGCAwtZKpU0c5rhKPF/3CRWH2gDY5lXru8cl
X1jTz7cBDNs9SWRdIXdaWmHI8WTVzWL7jVa0yUz16tIlEN3u1l6hqrZpJzFjf5GX
QeXpxltgJd54R+NscRSixvs0bVK2vy80Q5PDUAuAEB0m
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFWzCCA0OgAwIBAgIQTfQrldHumzpMLrM7jRBd1jANBgkqhkiG9w0BAQsFADBm
MQswCQYDVQQGEwJVUzEzMDEGA1UEChMqKFNUQUdJTkcpIEludGVybmV0IFNlY3Vy
aXR5IFJlc2VhcmNoIEdyb3VwMSIwIAYDVQQDExkoU1RBR0lORykgUHJldGVuZCBQ
ZWFyIFgxMB4XDTIwMDkwNDAwMDAwMFoXDTI1MDkxNTE2MDAwMFowWTELMAkGA1UE
BhMCVVMxIDAeBgNVBAoTFyhTVEFHSU5HKSBMZXQncyBFbmNyeXB0MSgwJgYDVQQD
Ex8oU1RBR0lORykgQXJ0aWZpY2lhbCBBcHJpY290IFIzMIIBIjANBgkqhkiG9w0B
AQEFAAOCAQ8AMIIBCgKCAQEAu6TR8+74b46mOE1FUwBrvxzEYLck3iasmKrcQkb+
gy/z9Jy7QNIAl0B9pVKp4YU76JwxF5DOZZhi7vK7SbCkK6FbHlyU5BiDYIxbbfvO
L/jVGqdsSjNaJQTg3C3XrJja/HA4WCFEMVoT2wDZm8ABC1N+IQe7Q6FEqc8NwmTS
nmmRQm4TQvr06DP+zgFK/MNubxWWDSbSKKTH5im5j2fZfg+j/tM1bGaczFWw8/lS
nukyn5J2L+NJYnclzkXoh9nMFnyPmVbfyDPOc4Y25aTzVoeBKXa/cZ5MM+WddjdL
biWvm19f1sYn1aRaAIrkppv7kkn83vcth8XCG39qC2ZvaQIDAQABo4IBEDCCAQww
DgYDVR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAS
BgNVHRMBAf8ECDAGAQH/AgEAMB0GA1UdDgQWBBTecnpI3zHDplDfn4Uj31c3S10u
ZTAfBgNVHSMEGDAWgBS182Xy/rAKkh/7PH3zRKCsYyXDFDA2BggrBgEFBQcBAQQq
MCgwJgYIKwYBBQUHMAKGGmh0dHA6Ly9zdGcteDEuaS5sZW5jci5vcmcvMCsGA1Ud
HwQkMCIwIKAeoByGGmh0dHA6Ly9zdGcteDEuYy5sZW5jci5vcmcvMCIGA1UdIAQb
MBkwCAYGZ4EMAQIBMA0GCysGAQQBgt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCN
DLam9yN0EFxxn/3p+ruWO6n/9goCAM5PT6cC6fkjMs4uas6UGXJjr5j7PoTQf3C1
vuxiIGRJC6qxV7yc6U0X+w0Mj85sHI5DnQVWN5+D1er7mp13JJA0xbAbHa3Rlczn
y2Q82XKui8WHuWra0gb2KLpfboYj1Ghgkhr3gau83pC/WQ8HfkwcvSwhIYqTqxoZ
Uq8HIf3M82qS9aKOZE0CEmSyR1zZqQxJUT7emOUapkUN9poJ9zGc+FgRZvdro0XB
yphWXDaqMYph0DxW/10ig5j4xmmNDjCRmqIKsKoWA52wBTKKXK1na2ty/lW5dhtA
xkz5rVZFd4sgS4J0O+zm6d5GRkWsNJ4knotGXl8vtS3X40KXeb3A5+/3p0qaD215
Xq8oSNORfB2oI1kQuyEAJ5xvPTdfwRlyRG3lFYodrRg6poUBD/8fNTXMtzydpRgy
zUQZh/18F6B/iW6cbiRN9r2Hkh05Om+q0/6w0DdZe+8YrNpfhSObr/1eVZbKGMIY
qKmyZbBNu5ysENIK5MPc14mUeKmFjpN840VR5zunoU52lqpLDua/qIM8idk86xGW
xx2ml43DO/Ya/tVZVok0mO0TUjzJIfPqyvr455IsIut4RlCR9Iq0EDTve2/ZwCuG
hSjpTUFGSiQrR2JK2Evp+o6AETUkBCO1aw0PpQBPDQ==
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFVDCCBDygAwIBAgIRAO1dW8lt+99NPs1qSY3Rs8cwDQYJKoZIhvcNAQELBQAw
cTELMAkGA1UEBhMCVVMxMzAxBgNVBAoTKihTVEFHSU5HKSBJbnRlcm5ldCBTZWN1
cml0eSBSZXNlYXJjaCBHcm91cDEtMCsGA1UEAxMkKFNUQUdJTkcpIERvY3RvcmVk
IER1cmlhbiBSb290IENBIFgzMB4XDTIxMDEyMDE5MTQwM1oXDTI0MDkzMDE4MTQw
M1owZjELMAkGA1UEBhMCVVMxMzAxBgNVBAoTKihTVEFHSU5HKSBJbnRlcm5ldCBT
ZWN1cml0eSBSZXNlYXJjaCBHcm91cDEiMCAGA1UEAxMZKFNUQUdJTkcpIFByZXRl
bmQgUGVhciBYMTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBALbagEdD
Ta1QgGBWSYkyMhscZXENOBaVRTMX1hceJENgsL0Ma49D3MilI4KS38mtkmdF6cPW
nL++fgehT0FbRHZgjOEr8UAN4jH6omjrbTD++VZneTsMVaGamQmDdFl5g1gYaigk
kmx8OiCO68a4QXg4wSyn6iDipKP8utsE+x1E28SA75HOYqpdrk4HGxuULvlr03wZ
GTIf/oRt2/c+dYmDoaJhge+GOrLAEQByO7+8+vzOwpNAPEx6LW+crEEZ7eBXih6V
P19sTGy3yfqK5tPtTdXXCOQMKAp+gCj/VByhmIr+0iNDC540gtvV303WpcbwnkkL
YC0Ft2cYUyHtkstOfRcRO+K2cZozoSwVPyB8/J9RpcRK3jgnX9lujfwA/pAbP0J2
UPQFxmWFRQnFjaq6rkqbNEBgLy+kFL1NEsRbvFbKrRi5bYy2lNms2NJPZvdNQbT/
2dBZKmJqxHkxCuOQFjhJQNeO+Njm1Z1iATS/3rts2yZlqXKsxQUzN6vNbD8KnXRM
EeOXUYvbV4lqfCf8mS14WEbSiMy87GB5S9ucSV1XUrlTG5UGcMSZOBcEUpisRPEm
QWUOTWIoDQ5FOia/GI+Ki523r2ruEmbmG37EBSBXdxIdndqrjy+QVAmCebyDx9eV
EGOIpn26bW5LKerumJxa/CFBaKi4bRvmdJRLAgMBAAGjgfEwge4wDgYDVR0PAQH/
BAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFLXzZfL+sAqSH/s8ffNE
oKxjJcMUMB8GA1UdIwQYMBaAFAhX2onHolN5DE/d4JCPdLriJ3NEMDgGCCsGAQUF
BwEBBCwwKjAoBggrBgEFBQcwAoYcaHR0cDovL3N0Zy1kc3QzLmkubGVuY3Iub3Jn
LzAtBgNVHR8EJjAkMCKgIKAehhxodHRwOi8vc3RnLWRzdDMuYy5sZW5jci5vcmcv
MCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQBgt8TAQEBMA0GCSqGSIb3DQEB
CwUAA4IBAQB7tR8B0eIQSS6MhP5kuvGth+dN02DsIhr0yJtk2ehIcPIqSxRRmHGl
4u2c3QlvEpeRDp2w7eQdRTlI/WnNhY4JOofpMf2zwABgBWtAu0VooQcZZTpQruig
F/z6xYkBk3UHkjeqxzMN3d1EqGusxJoqgdTouZ5X5QTTIee9nQ3LEhWnRSXDx7Y0
ttR1BGfcdqHopO4IBqAhbkKRjF5zj7OD8cG35omywUbZtOJnftiI0nFcRaxbXo0v
oDfLD0S6+AC2R3tKpqjkNX6/91hrRFglUakyMcZU/xleqbv6+Lr3YD8PsBTub6lI
oZ2lS38fL18Aon458fbc0BPHtenfhKj5
-----END CERTIFICATE-----
(Also: You are actually using an ECDSA account key, correct?)
Yes, that's the default for win-acme. The account used for this run was https://acme-staging-v02.api.letsencrypt.org/acme/acct/93866614, if that helps