From: "Massimo S." Received: from mail2.quasarbbs.net ([80.86.52.115] verified) by 2rosenthals.com (CommuniGate Pro SMTP 5.4.10) with ESMTP id 3291660 for ecs-isp@2rosenthals.com; Wed, 05 Aug 2026 16:22:45 -0400 DKIM-Signature: v=1; q=dns/txt; a=rsa-sha256; c=relaxed/relaxed; s=default; d=ecomstation.it; bh=FPi1Yq/dsKsh0s6FsEHwCs59KBaEkxqYTTkBY88vQ5I=; h=Return-Path:From:To:Subject:Date:Message-ID; b=HaR9hmiL1oB3mb+lqPB4W5X0qSO3bamTZUVnYzxDcfeZuB/Kk7Er6ildexh9yrgqmjjc3 77QCftjuiy8FRbYHYU/ZtA9QAL2G87TX9OAxCvc9FWZMWtPTt2seL+ZmExcKd5OJ7OukMpL tPiD0B/XmnYdEC4NYNOT0OIwiUYx/M9QC5uCRK2G7Q+nRwEdaH/TRBFlMpUt4ahHagrHexu oIaf8ctdRvq5oCCdw88MsyGLRUEn5D23kytOeulAlNprc8a/VVgNbgFfaRmFgvesWUkD6Nx q4M8eFIMqVPnUsPE4HxsbOkvnYNbbe7+rsShONxffa+nX4DmuG5BDcJdt46A== Authentication-Results: srv2; spf=none smtp.helo=[192.168.10.199]; spf=pass smtp.mailfrom=ecomstation.it Received: from [192.168.10.199] (dtp [192.168.10.199]) by srv2 (Weasel v3.143) for ; Wed, 05 Aug 2026 22:22:43 -0000 Reply-To: ml@ecomstation.it Subject: Re: [eCS-ISP] uacme 1.2.4 issue - update To: eCS ISP Mailing List References: Organization: Massimo S. Message-ID: Date: Wed, 5 Aug 2026 22:22:40 +0200 User-Agent: Mozilla/5.0 (OS/2; U; Warp 4.5; it-IT; rv:1.7.13) Gecko/20060424 Thunderbird/1.0.8 Mnenhy/0.7.4.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: it Content-Transfer-Encoding: 8bit Il 05/08/2026 22:08, Massimo S. ha scritto: > > > Il 05/08/2026 21:06, Paul Smedley ha scritto: >> Hi Max, >> >> On 5/8/26 23:53, Massimo S. wrote: >>> Il 05/08/2026 10:57, Massimo S. ha scritto: >>>> >>>> >>>> Il 05/08/2026 01:13, Peter Moylan ha scritto: >>>>> On 05/08/26 07:47, Paul Smedley wrote: >>>>>> On 4/8/26 22:31, Massimo S. wrote: >>>>>>> Il 09/06/2026 10:50, Paul Smedley ha scritto: >>>>> >>>>>>>> My guess would be the ca-certs rpm package is either missing or out >>>>>>>> of date. >>>>> >>>>>>> this is what i believed too.. >>>>>>> i've downloaded the new cacert.pem but this doesnt' help. >>>>>>> >>>>>>> Maybe uacme starting from version 1.2.4 (like 1.8.1 by Andrey too) has >>>>>>> some issue with /2 paths. >>>>>>> >>>>>>> cp: impossibile eseguire stat di >>>>>>> 'c:etcssluacme/www.myfakedomain.com/cert.pem': No such file or directory >>>>>>> >>>>>>> What's that "C:etcssluacm..."? >>>>>>> >>>>>> My 'guess' would be a shell issue.  Is this only when your scheduler >>>>>> starts uacme? Perhaps the schedule is overriding the statemetnts in >>>>>> config.sys that set *SHELL* to sh.exe >>>>> >>>>> That sounds like a Unixism. My config.sys has >>>>>        SET OS2_SHELL=C:\OS2\CMD.EXE >>>>> >>>>> I don't use cron, so I don't know whether cron overrides that. >>>>> >>>>> I've just realised that my updating script explicitly specifies the shell: >>>>>       Path and file name: cmd.exe >>>>>       Parameters:    /C issue_pmoylan.org.cmd >>>> >>>> Copilot say that UACME 1.0.19 have an its own https client that do direct >>>> requests to LE's server, while later versions use external libcurl. >>>> (i don't have any libcurl on the entire VM, but this do not explain >>>> why the renewal works if started manually, damn..) >>>> >>>> This stuff about the internal https client can only be confirmed by Paul >>>> or Andrey that did the portings. >>>> I've written to Andrey and also to Nicola Di Lieto (the developer >>>> of UACME), but i still have no answers, we are in august, ppl are on holidays.. >>> >>> Nicola Di Lieto answered to the email, NO, UACME 1.0.19 don't have an >>> internal https service/code, it have allways used libcurl. >>> >>> So who knows if libcurl has been statically linked into 1.0.19, >>> but not in the newer versions? >>> >>> If so a libcurl statically linked build should fix the cron issue. >>> >> Sounds more like BEGINLIBPATH should fix your cron issue, ie your cron isn't respecting the system LIBPATH. >> >> Cheers, >> >> Paul > > no, same result, i added in the cmd: > > @x: > @cd x:\uacme > @SET LIBPATHSTRICT=T > @set beginlibpath=x:\uacme; > > uacme: fetching directory at https://acme-v02.api.letsencrypt.org/directory > uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory failed: Problem with the SSL CA cert > (path? access rights?) > uacme: curl_get: waiting 5 seconds before retrying > > is it possible to understand what changed in the porting from 1.0.19 to 1.2.4? > > massimo i've now tried also to put under libpath x:\uacme in config.sys i rebooted the VM, retried, same issue i believe that 1.2.4 and 1.8.1 lack something compeared to 1.0.19, they have been tested only by starting it manually and not scheduled Andrey is not answering, maybe he's on holidays massimo