# Update your client software to continue using Let's Encrypt

**URL:** <https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833>\
**Category:** Help\
**Created:** [January 17, 2020, 5:59am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833 "2020-01-17T05:59:08Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tekchand](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@Tekchand](https://community.letsencrypt.org/u/Tekchand)\
**Post date:** [January 17, 2020, 5:59am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/1 "2020-01-17T05:59:08Z")

</div>

Hello Team,

We got e-mail that we need to upgrade ACMEv1 to ACMEv2. We are using ubuntu 16.04/18.04. We tried to find out the method and visit some article but no success.

Can you please help us how we can upgrade our ACMEv1 protocol to ACMEv2?

We have upgraded our certbot to version `0.31` but still showing `acme-v01.api.letsencrypt.org` folder in `/etc/letsencrypt` folder. But we are assuming it should be `acme-v02`  
Below are the version of certbot and `python3-acme`:

```auto
xyz@abc:/etc/letsencrypt/accounts# certbot --version
certbot 0.31.0
xyz@abc:/etc/letsencrypt/accounts# dpkg -l python3-acme
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name Version Architecture Description
+++-================================-=====================-=====================-=====================================================================
ii python3-acme 0.31.0-2+ubuntu18.04. all ACME protocol library for Python 3

```

Any help or guidance will be appriciated.

Thanks.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 17, 2020, 6:49am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/2 "2020-01-17T06:49:48Z")

</div>

> [@Tekchand](#):
>
> We have upgraded our certbot to version `0.31` but still showing `acme-v01.api.letsencrypt.org` folder in `/etc/letsencrypt` folder. But we are assuming it should be `acme-v02`

If you run a:

`grep -R acme-v01 /etc/letsencrypt/`

Does it come up with one or more `server` directives in configuration files? It could be `/etc/letsencrypt/cli.ini` itself, but could also be hardcoded in renewal configuration files.

I think its best _not_ to hardcode the `server` option when only Let's Encrypt ACME server is used in combination with `certbot`, as `certbot` uses LE by default. Only if you have some sort of test domain only using the **staging** server, I can understand you'd want to hardcode that. But if you're just using the default production ACME server, don't hardcode it anywhere.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [January 17, 2020, 6:59am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/3 "2020-01-17T06:59:07Z")

</div>

> [@Tekchand](#):
>
> We have upgraded our certbot to version `0.31` but still showing `acme-v01.api.letsencrypt.org` folder in `/etc/letsencrypt` folder.

Where? If you mean in `/etc/letsencrypt/accounts/`, that's normal. 🙂 Certbot just doesn't delete the `acme-v01.api.letsencrypt.org` account files. When you first interact with the ACMEv2 API, it will create an `acme-v02.api.letsencrypt.org` directory and copy or symlink your Let's Encrypt account data to it.

---

<div class="post-metadata">

**Author:** ![Tekchand](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@Tekchand](https://community.letsencrypt.org/u/Tekchand)\
**Post date:** [January 17, 2020, 7:02am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/4 "2020-01-17T07:02:36Z")

</div>

@mnordhoff, Thank you for your response.

Can you please help me how we can verify that our certbot will use ACMEv2? Like in dry-run we can check it or not or any other method?

So we can provide evidence to our higher management. We already shared the version of my `certobot` and `python3-acme` in first post.

Thanks.

---

<div class="post-metadata">

**Author:** ![Tekchand](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@Tekchand](https://community.letsencrypt.org/u/Tekchand)\
**Post date:** [January 17, 2020, 7:06am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/5 "2020-01-17T07:06:48Z")

</div>

@Osiris,

> [@Osiris](#):
>
> grep -R acme-v01 /etc/letsencrypt/

```nohighlight
/etc/letsencrypt/accounts/acme-v01.api.letsencrypt.org/directory/17200e4d2e5e8008c5d231590c0a1e4e/regr.json:{[redacted]}

```

Can you please help me how we can verify that certbot will user ACMEv2?

Thanks.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [January 17, 2020, 7:15am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/6 "2020-01-17T07:15:21Z")

</div>

I edited your post to remove the contents of the file because I’m not sure if they’re sensitive.

If the key in the file is the public key, that’s fine.

If it’s the private key, that is extremely bad.

---

<div class="post-metadata">

**Author:** ![Tekchand](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@Tekchand](https://community.letsencrypt.org/u/Tekchand)\
**Post date:** [January 17, 2020, 7:22am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/7 "2020-01-17T07:22:29Z")

</div>

@mnordhoff, Thanks.

Now when i run dry run for my one staging domain and check the logs its seems certbot is using ACMEv2 protocol. Below are the some logs:

```auto
Server: nginx
Date: Fri, 17 Jan 2020 07:19:23 GMT
Content-Type: application/pem-certificate-chain
Content-Length: 3563
Connection: keep-alive
Cache-Control: public, max-age=0, no-cache
Link: <https://acme-staging-v02.api.letsencrypt.org/directory>;rel="index"

```

If you confirm same then it will be good for me.

Thanks.

---

<div class="post-metadata">

**Author:** ![orangepizza](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/orangepizza/32/19597_2.png) [@orangepizza](https://community.letsencrypt.org/u/orangepizza)\
**Post date:** [January 17, 2020, 9:42am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/8 "2020-01-17T09:42:14Z")

</div>

is that mean while we can’t make new account by acme v1, but still use account created by acmev2 on acmev1 only client?

---

<div class="post-metadata">

**Author:** ![bruncsak](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruncsak/32/18414_2.png) [@bruncsak](https://community.letsencrypt.org/u/bruncsak)\
**Post date:** [January 17, 2020, 11:08am UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/9 "2020-01-17T11:08:39Z")

</div>

The restriction is on the protocol version itself but the backend data store is shared, I guess.

---

<div class="post-metadata">

**Author:** ![gilgongo](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/gilgongo/32/24350_2.png) [@gilgongo](https://community.letsencrypt.org/u/gilgongo)\
**Post date:** [January 31, 2020, 4:38pm UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/10 "2020-01-31T16:38:55Z")

</div>

I’ve got a similar issue to the OP, having had a warning email about this.

`grep -R acme-v01 /etc/letsencrypt/`

shows:

```
/etc/letsencrypt/renewal/unifi.bakerbates.com.conf:server = https://acme-v01.api.letsencrypt.org/directory
/etc/letsencrypt/accounts/acme-v01.api.letsencrypt.org/directory/b2efdc9d....118df40c0e/regr.json:{"body": {}, "uri": "https://acme-v01.api.letsencrypt.org/acme/reg/61974310", "new_authzr_uri": "https://acme-v01.api.letsencrypt.org/acme/new-authz"}

```

I’m running certbot 0.28.0 on Debian 9.

What do I need to do to switch to API 2.0?

**EDIT** : Having read up some more on this, it seems that compatible clients will simply switch to v2.0 automatically. The fact that I haven’t makes me think it’s because our outgoing proxy is preventing certbot accessing [acme-v02.api.letsencrypt.org](http://acme-v02.api.letsencrypt.org). Allowing this might solve my problem but so far I’m not having any luck.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 1, 2020, 4:38pm UTC](https://community.letsencrypt.org/t/update-your-client-software-to-continue-using-lets-encrypt/110833/11 "2020-03-01T16:38:59Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
