From: "Massimo S." Received: from mail2.quasarbbs.net ([80.86.52.115] verified) by 2rosenthals.com (CommuniGate Pro SMTP 5.4.10) with ESMTP id 3291633 for ecs-isp@2rosenthals.com; Wed, 05 Aug 2026 16:08:33 -0400 DKIM-Signature: v=1; q=dns/txt; a=rsa-sha256; c=relaxed/relaxed; s=default; d=ecomstation.it; bh=iZGwgWxPqzaR/5wMLVEQgXhfL7OCA+7n3ZN/r0kNMrw=; h=Return-Path:From:To:Subject:Date:Message-ID; b=al2iF6skhgSVVQCszZeWnVvDiQh8UOGefr4rbOAniNMJwDvMzo+l2P5VL0WCzyOGdJKRM 4uD2JNnHz8gYzrxhy20dVQg83JZj5sD+Pbti0Wa564nbYEt1zOwXnayeNWI0GMvVUzkdPn0 aC814eiQlav14qsuceTNOVhKUMMuVTCptVPAoUEyo5whxWSEY1usS0F8BaZfPIXHR29bLGW OASaA+o2Qs8NdcSqfYoJoIANIzEoIHtHn1LEQC9aUb9PjsAgnO3jgJH0WNnW/Evt56fFuuh oNoq39GdjZKaA4PjL7K4J4haeUsb4DAhl3jriWLHe3BOYKlt/4u8OBKx+1Jg== Authentication-Results: srv2; spf=none smtp.helo=[192.168.10.199]; spf=pass smtp.mailfrom=ecomstation.it Received: from [192.168.10.199] (dtp [192.168.10.199]) by srv2 (Weasel v3.143) for ; Wed, 05 Aug 2026 22:08:31 -0000 Reply-To: ml@ecomstation.it Subject: Re: [eCS-ISP] uacme 1.2.4 issue - update To: eCS ISP Mailing List References: Organization: Massimo S. Message-ID: <88756c57-a8f3-60ba-0b1c-957ce42f97b6@ecomstation.it> Date: Wed, 5 Aug 2026 22:08:28 +0200 User-Agent: Mozilla/5.0 (OS/2; U; Warp 4.5; it-IT; rv:1.7.13) Gecko/20060424 Thunderbird/1.0.8 Mnenhy/0.7.4.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: it Content-Transfer-Encoding: 8bit Il 05/08/2026 21:06, Paul Smedley ha scritto: > Hi Max, > > On 5/8/26 23:53, Massimo S. wrote: >> Il 05/08/2026 10:57, Massimo S. ha scritto: >>> >>> >>> Il 05/08/2026 01:13, Peter Moylan ha scritto: >>>> On 05/08/26 07:47, Paul Smedley wrote: >>>>> On 4/8/26 22:31, Massimo S. wrote: >>>>>> Il 09/06/2026 10:50, Paul Smedley ha scritto: >>>> >>>>>>> My guess would be the ca-certs rpm package is either missing or out >>>>>>> of date. >>>> >>>>>> this is what i believed too.. >>>>>> i've downloaded the new cacert.pem but this doesnt' help. >>>>>> >>>>>> Maybe uacme starting from version 1.2.4 (like 1.8.1 by Andrey too) has >>>>>> some issue with /2 paths. >>>>>> >>>>>> cp: impossibile eseguire stat di >>>>>> 'c:etcssluacme/www.myfakedomain.com/cert.pem': No such file or directory >>>>>> >>>>>> What's that "C:etcssluacm..."? >>>>>> >>>>> My 'guess' would be a shell issue.  Is this only when your scheduler >>>>> starts uacme? Perhaps the schedule is overriding the statemetnts in >>>>> config.sys that set *SHELL* to sh.exe >>>> >>>> That sounds like a Unixism. My config.sys has >>>>        SET OS2_SHELL=C:\OS2\CMD.EXE >>>> >>>> I don't use cron, so I don't know whether cron overrides that. >>>> >>>> I've just realised that my updating script explicitly specifies the shell: >>>>       Path and file name: cmd.exe >>>>       Parameters:    /C issue_pmoylan.org.cmd >>> >>> Copilot say that UACME 1.0.19 have an its own https client that do direct >>> requests to LE's server, while later versions use external libcurl. >>> (i don't have any libcurl on the entire VM, but this do not explain >>> why the renewal works if started manually, damn..) >>> >>> This stuff about the internal https client can only be confirmed by Paul >>> or Andrey that did the portings. >>> I've written to Andrey and also to Nicola Di Lieto (the developer >>> of UACME), but i still have no answers, we are in august, ppl are on holidays.. >> >> Nicola Di Lieto answered to the email, NO, UACME 1.0.19 don't have an >> internal https service/code, it have allways used libcurl. >> >> So who knows if libcurl has been statically linked into 1.0.19, >> but not in the newer versions? >> >> If so a libcurl statically linked build should fix the cron issue. >> > Sounds more like BEGINLIBPATH should fix your cron issue, ie your cron isn't respecting the system LIBPATH. > > Cheers, > > Paul no, same result, i added in the cmd: @x: @cd x:\uacme @SET LIBPATHSTRICT=T @set beginlibpath=x:\uacme; uacme: fetching directory at https://acme-v02.api.letsencrypt.org/directory uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory failed: Problem with the SSL CA cert (path? access rights?) uacme: curl_get: waiting 5 seconds before retrying is it possible to understand what changed in the porting from 1.0.19 to 1.2.4? massimo