# Mail about TLS-SNI-01 end of life

**URL:** <https://community.letsencrypt.org/t/mail-about-tls-sni-01-end-of-life/82933>\
**Category:** Help\
**Created:** [January 18, 2019, 10:14am UTC](https://community.letsencrypt.org/t/mail-about-tls-sni-01-end-of-life/82933 "2019-01-18T10:14:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![letsdebug](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@letsdebug](https://community.letsencrypt.org/u/letsdebug)\
**Post date:** [January 18, 2019, 10:14am UTC](https://community.letsencrypt.org/t/mail-about-tls-sni-01-end-of-life/82933/1 "2019-01-18T10:14:34Z")

</div>

Hello,  
I just received the mail about TLS-SNI-01 end of life.

I use Let’s Encrypt on Plesk servers; Plesk knowledge base says they never used TLS-SNI-01: [https://talk.plesk.com/threads/lets-encrypt-issue-with-tls-sni-01.346524/](https://talk.plesk.com/threads/lets-encrypt-issue-with-tls-sni-01.346524/)

At this point I’m really confused… I have lots of server and lots of domains; is there any way to know which domains the mail refers to?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [January 18, 2019, 10:37am UTC](https://community.letsencrypt.org/t/mail-about-tls-sni-01-end-of-life/82933/2 "2019-01-18T10:37:57Z")

</div>

Hi @letsdebug

> [@letsdebug](#):
>
> Plesk knowledge base says they never used TLS-SNI-01

if you don't use tls-sni-01 - validation, ignore the mail.

http-01 / dns-01 works.

---

<div class="post-metadata">

**Author:** ![gmx](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/gmx/32/29007_2.png) [@gmx](https://community.letsencrypt.org/u/gmx)\
**Post date:** [January 18, 2019, 11:01am UTC](https://community.letsencrypt.org/t/mail-about-tls-sni-01-end-of-life/82933/3 "2019-01-18T11:01:15Z")

</div>

We received the same email but I honestly am not sure whether we’ve ever used TLS-SNI-01 or not. We use certbot on CentOS 7 - what is the default method of auth please?

Thanks

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [January 18, 2019, 11:06am UTC](https://community.letsencrypt.org/t/mail-about-tls-sni-01-end-of-life/82933/4 "2019-01-18T11:06:31Z")

</div>

> [@gmx](#):
>
> what is the default method of auth please?

That depends on your certbot version (old: tls-sni was standard) and your config.

Check your config / renew files. "standalone" and "tls-sni" is critical.

---

<div class="post-metadata">

**Author:** ![gmx](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/gmx/32/29007_2.png) [@gmx](https://community.letsencrypt.org/u/gmx)\
**Post date:** [January 18, 2019, 12:36pm UTC](https://community.letsencrypt.org/t/mail-about-tls-sni-01-end-of-life/82933/5 "2019-01-18T12:36:23Z")

</div>

> [@JuergenAuer](#):
>
> That depends on your certbot version (old: tls-sni was standard) and your config.

So presumably the version in the RHEL7 repos is up to date? In which case presumably I can just update certbot from there?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [January 18, 2019, 12:38pm UTC](https://community.letsencrypt.org/t/mail-about-tls-sni-01-end-of-life/82933/6 "2019-01-18T12:38:25Z")

</div>

> [@gmx](#):
>
> RHEL7

To get up-to-date Certbot on EL7 and its derivatives, you need to install it from EPEL, as shown here: [https://certbot.eff.org/lets-encrypt/centosrhel7-other](https://certbot.eff.org/lets-encrypt/centosrhel7-other)

The RHEL repos themselves may sport a non-current version.

What's important to you is for Certbot to be 0.28 or higher:

```
certbot --version

```

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [February 17, 2019, 12:38pm UTC](https://community.letsencrypt.org/t/mail-about-tls-sni-01-end-of-life/82933/7 "2019-02-17T12:38:27Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
