Mail about TLS-SNI-01 end of life

I just received the mail about TLS-SNI-01 end of life.

I use Let’s Encrypt on Plesk servers; Plesk knowledge base says they never used TLS-SNI-01:

At this point I’m really confused… I have lots of server and lots of domains; is there any way to know which domains the mail refers to?

Hi @letsdebug

if you don't use tls-sni-01 - validation, ignore the mail.

http-01 / dns-01 works.

We received the same email but I honestly am not sure whether we’ve ever used TLS-SNI-01 or not. We use certbot on CentOS 7 - what is the default method of auth please?


That depends on your certbot version (old: tls-sni was standard) and your config.

Check your config / renew files. “standalone” and “tls-sni” is critical.

So presumably the version in the RHEL7 repos is up to date? In which case presumably I can just update certbot from there?

To get up-to-date Certbot on EL7 and its derivatives, you need to install it from EPEL, as shown here:

The RHEL repos themselves may sport a non-current version.

What’s important to you is for Certbot to be 0.28 or higher:

certbot --version

