From: "Paul Smedley" Received: from vps.smedley.id.au ([23.238.44.164] verified) by 2rosenthals.com (CommuniGate Pro SMTP 5.4.10) with ESMTP id 3291763 for ecs-isp@2rosenthals.com; Wed, 05 Aug 2026 17:11:28 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=smedley.id.au; s=default; t=1785963788; bh=9A8CT/F351iyVpxDPZyS1323EEEU8EiDkvoioYR2fqg=; h=Date:Subject:To:References:From:In-Reply-To:From; b=lInO/zx76jYXwPrNv5orytALZW3cHB2kWhyn6XC1u6LMxjqcV1xJCd2n8dCh1IQ+z 9C9NUpLvJX0NKxA1ugkA1vS8CzpzVKFQYdeOVAbjkZUFcvUpQxpECPOX3r7b1TIFOg Ua7VqpxY9vfW7831/IcLeCzjNcATr3xq0tjAWZaY= Received: from [192.168.245.251] (smedley.org [45.249.117.21]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by vps.smedley.id.au (Postfix) with ESMTPSA id 6D50D2009F for ; Thu, 06 Aug 2026 06:33:08 +0930 (ACST) Message-ID: <23cafd54-e867-4068-81a8-6517e33f2d7c@smedley.id.au> Date: Thu, 6 Aug 2026 06:33:05 +0930 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [eCS-ISP] uacme 1.2.4 issue - update To: eCS ISP Mailing List References: Content-Language: en-AU In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit I don't have easy access to an OS/2 box where I am right now, but what does chkdll32.exe uacme.exe on the 1.0.19 & 1.2.4 executables say? My guess is that 1.0.19 had libcurl statically linked and 1.2.4 has it dynamically linked. dynamically linked is preferred as you get security updates for free On 6/8/26 05:38, Massimo S. wrote: > > > Il 05/08/2026 21:06, Paul Smedley ha scritto: >> Hi Max, >> >> On 5/8/26 23:53, Massimo S. wrote: >>> Il 05/08/2026 10:57, Massimo S. ha scritto: >>>> >>>> >>>> Il 05/08/2026 01:13, Peter Moylan ha scritto: >>>>> On 05/08/26 07:47, Paul Smedley wrote: >>>>>> On 4/8/26 22:31, Massimo S. wrote: >>>>>>> Il 09/06/2026 10:50, Paul Smedley ha scritto: >>>>> >>>>>>>> My guess would be the ca-certs rpm package is either missing or >>>>>>>> out >>>>>>>> of date. >>>>> >>>>>>> this is what i believed too.. >>>>>>> i've downloaded the new cacert.pem but this doesnt' help. >>>>>>> >>>>>>> Maybe uacme starting from version 1.2.4 (like 1.8.1 by Andrey >>>>>>> too) has >>>>>>> some issue with /2 paths. >>>>>>> >>>>>>> cp: impossibile eseguire stat di >>>>>>> 'c:etcssluacme/www.myfakedomain.com/cert.pem': No such file or >>>>>>> directory >>>>>>> >>>>>>> What's that "C:etcssluacm..."? >>>>>>> >>>>>> My 'guess' would be a shell issue.  Is this only when your scheduler >>>>>> starts uacme? Perhaps the schedule is overriding the statemetnts in >>>>>> config.sys that set *SHELL* to sh.exe >>>>> >>>>> That sounds like a Unixism. My config.sys has >>>>>        SET OS2_SHELL=C:\OS2\CMD.EXE >>>>> >>>>> I don't use cron, so I don't know whether cron overrides that. >>>>> >>>>> I've just realised that my updating script explicitly specifies >>>>> the shell: >>>>>       Path and file name: cmd.exe >>>>>       Parameters:    /C issue_pmoylan.org.cmd >>>> >>>> Copilot say that UACME 1.0.19 have an its own https client that do >>>> direct >>>> requests to LE's server, while later versions use external libcurl. >>>> (i don't have any libcurl on the entire VM, but this do not explain >>>> why the renewal works if started manually, damn..) >>>> >>>> This stuff about the internal https client can only be confirmed by >>>> Paul >>>> or Andrey that did the portings. >>>> I've written to Andrey and also to Nicola Di Lieto (the developer >>>> of UACME), but i still have no answers, we are in august, ppl are >>>> on holidays.. >>> >>> Nicola Di Lieto answered to the email, NO, UACME 1.0.19 don't have an >>> internal https service/code, it have allways used libcurl. >>> >>> So who knows if libcurl has been statically linked into 1.0.19, >>> but not in the newer versions? >>> >>> If so a libcurl statically linked build should fix the cron issue. >>> >> Sounds more like BEGINLIBPATH should fix your cron issue, ie your >> cron isn't respecting the system LIBPATH. >> >> Cheers, >> >> Paul > > no, same result, i added in the cmd: > > @x: > @cd x:\uacme > @SET LIBPATHSTRICT=T > @set beginlibpath=x:\uacme; > > uacme: fetching directory at > https://acme-v02.api.letsencrypt.org/directory > uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory > failed: Problem with the SSL CA cert (path? access rights?) > uacme: curl_get: waiting 5 seconds before retrying > > is it possible to understand what changed in the porting from 1.0.19 > to 1.2.4? > > massimo > > =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= > This message is sent to you because you are subscribed to >  the mailing list . > To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to > To switch to the INDEX mode, E-mail to > Send administrative queries to > To subscribe (new addresses), E-mail to: > and reply to the confirmation email. > Web archives are publicly available at: http://lists.2rosenthals.com > > This list is hosted by Rosenthal & Rosenthal, LLC > P.O. Box 281, Deer Park, NY 11729-0281. Non- > electronic communications related to content > contained in these messages should be directed > to the above address. (CAN-SPAM Act of 2003) > > =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= >