Mailing List ecs-isp@2rosenthals.com Archived Message #1349

From: "Peter Moylan" <ecs-isp@2rosenthals.com> Full Headers
Undecoded message
Subject: Re: [eCS-ISP] uacme 1.2.4 issue
Date: Tue, 9 Jun 2026 21:03:53 +1000
To: eCS ISP Mailing List <ecs-isp@2rosenthals.com>

On 09/06/26 18:06, Massimo S. wrote:
Hi all,

for a LE certificate renewal if i use uacme 1.2.4 i get this:

uacme: version 1.2.4 starting on Tue, 09 Jun 2026 09:34:39
...
...
uacme: fetching directory at https://acme-v02.api.letsencrypt.org/directory
uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory
failed: Problem with the SSL CA cert (path? access rights?)
uacme: curl_get: waiting 5 seconds before retrying
uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory
failed: Problem with the SSL CA cert (path? access rights?)
uacme: curl_get: waiting 5 seconds before retrying
uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory
failed: Problem with the SSL CA cert (path? access rights?)
uacme: curl_get: waiting 5 seconds before retrying
uacme: acme_get: curl_get failed
uacme: failed to fetch directory at
https://acme-v02.api.letsencrypt.org/directory

while it works if i use uacme 1.0.9

i've seen that i'm using 1.0.9 on all VMs, i forgot about that..

Paul suggested out-of-date prerequisite software, and he might well be
right.

If that doesn't help, here is another possibility. We have seen in the
past that different versions of uacme make different assumptions about
default directories. The best defence against that is to make sure that
your own scripts use explicit paths instead of relying on the default
assumptions. Now that I think of it, I think I had to do that when
updating to version 1.2.4.

--
Peter Moylan                  peter@pmoylan.org
http://www.pmoylan.org

Subscribe: Feed, Digest, Index.
Unsubscribe
Mail to ListMaster