List ecs-isp@2rosenthals.com Arkiverade meddelande #963

Från: "Massimo S." <ecs-isp@2rosenthals.com> Meddelandehuvud
Oavkodat meddelande
Ämne: Re: [eCS-ISP] uacme 1.2.4 curl issue
Datum: Thu, 24 Oct 2024 18:41:06 +0200
Till: eCS ISP Mailing List <ecs-isp@2rosenthals.com>



Il 22/10/2024 23:45, Steven Levine ha scritto:
In <list-11130580@2rosenthals.com>, on 10/22/24
    at 05:24 PM, "Massimo S." <ecs-isp@2rosenthals.com> said:

Hi Massimo,

uacme -v issue www.mydomain.it -c c:/mptn/etc/ssl/uacme -h
hook_www_mydomain_it.cmd

and i got

uacme: c:/mptn/etc/ssl/uacme/private/www.mydomain.it/key.pem not found  *

This is normal.  Uacme is checking if the domain private key exists, so it
knows what to do next.

uacme: checking existence and expiration of
c:/mptn/etc/ssl/uacme/www.mydomain.it/cert.pem uacme:
c:/mptn/etc/ssl/uacme/www.mydomain.it/cert.pem does not exist ** uacme:
fetching directory at https://acme-v02.api.letsencrypt.org/directory

This is normal.  Uacme is checking if the cert exists so it knows what to
do next.

uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory
failed: SSL peer certificate or SSH remote  key was not OK uacme:
curl_get: waiting 5 seconds before retrying

I've seen this recently too.  It appears that Let's Encrypt is somewhat
overloaded recently.  There's nothing you can do other than retry until it
works.

It might be instructive to open

   https://acme-v02.api.letsencrypt.org/directory

in a browser.  The file contains a list of the actions that that LE
supports.

while if i don't delete key.pem and cert.pem
i get

All normal, best I can tell

while if i delete only cert.pem
i get the same

Again.  All normal other than the LE busy issue.

so i don't understand if uacme 1.2.4 is working correctly or not :-(

uacme is working correctly.  The problem is wih the LE server which
hopefully will not persist.

Steven

Hi Steven,

sorry, no
it's uacme 1.2.4 that have issues

i've just retried some minute ago and i got:

uacme: version 1.2.4 starting on Thu, 24 Oct 2024 18:26:52
uacme: loading key from c:/mptn/etc/ssl/uacme/private/key.pem
uacme: loading key from c:/mptn/etc/ssl/uacme/private/www.mydomain.it/key.pem
uacme: checking existence and expiration of c:/mptn/etc/ssl/uacme/www.mydomain.it/cert.pem
uacme: c:/mptn/etc/ssl/uacme/www.mydomain.it/cert.pem does not exist
uacme: fetching directory at https://acme-v02.api.letsencrypt.org/directory
uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory failed: SSL peer certificate or SSH remote key was not OK
uacme: curl_get: waiting 5 seconds before retrying
uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory failed: SSL peer certificate or SSH remote key was not OK
uacme: curl_get: waiting 5 seconds before retrying
uacme: curl_get: GET https://acme-v02.api.letsencrypt.org/directory failed: SSL peer certificate or SSH remote key was not OK
uacme: curl_get: waiting 5 seconds before retrying
uacme: acme_get: curl_get failed
uacme: failed to fetch directory at https://acme-v02.api.letsencrypt.org/directory


while with 1.0.9 it's successful:

uacme: version 1.0.19 starting on Thu, 24 Oct 2024 18:29:46
uacme: loading key from c:/mptn/etc/ssl/uacme/private/key.pem
uacme: loading key from c:/mptn/etc/ssl/uacme/private/www.mydomain.it/key.pem
uacme: checking existence and expiration of c:/mptn/etc/ssl/uacme/www.mydomain.it/cert.pem
uacme: c:/mptn/etc/ssl/uacme/www.mydomain.it/cert.pem does not exist
uacme: fetching directory at https://acme-v02.api.letsencrypt.org/directory
uacme: retrieving account at https://acme-v02.api.letsencrypt.org/acme/new-acct
uacme: account location: https://acme-v02.api.letsencrypt.org/acme/acct/68817448
uacme: creating new order for www.mydomain.it at https://acme-v02.api.letsencrypt.org/acme/new-order
uacme: order URL: https://acme-v02.api.letsencrypt.org/acme/order/68817448/316670748157
uacme: generating certificate request
uacme: finalizing order at https://acme-v02.api.letsencrypt.org/acme/finalize/68817448/316670748157
uacme: polling order status at https://acme-v02.api.letsencrypt.org/acme/order/68817448/316670748157
uacme: retrieving certificate at https://acme-v02.api.letsencrypt.org/acme/cert/04034ebd345d25544f216c79a4100e633ccc
uacme: saving certificate to c:/mptn/etc/ssl/uacme/www.mydomain.it/cert.pem.tmp
uacme: renaming c:/mptn/etc/ssl/uacme/www.mydomain.it/cert.pem.tmp to c:/mptn/etc/ssl/uacme/www.mydomain.it/cert.pem



massimo

Prenumerera: Sändning, Uppsamling, Index.
Stoppa prenumeration
Meddelande till ListMaster