<feed xmlns='http://www.w3.org/2005/Atom'>
<title>lacme/debian/patches/series, branch debian/buster</title>
<subtitle>Small ACME client written with process isolation and minimal privileges in mind</subtitle>
<link rel='alternate' type='text/html' href='http://git.guilhem.org/lacme/'/>
<entry>
<title>Use upstream certificate chain instead of an hardcoded one.</title>
<updated>2020-11-26T01:10:05+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-11-26T00:19:45+00:00</published>
<link rel='alternate' type='text/html' href='http://git.guilhem.org/lacme/commit/?id=f2514b36b8c9f519452106fbc84ca69f1955ada1'/>
<id>f2514b36b8c9f519452106fbc84ca69f1955ada1</id>
<content type='text'>
This is a breaking change.  The certificate indicated by 'CAfile' is no
longer used as is in 'certificate-chain' (along with the leaf cert).
The chain returned by the ACME v2 endpoint is used instead.  This allows
for more flexbility with respect to key/CA rotation, cf.
https://letsencrypt.org/2020/11/06/own-two-feet.html and
https://community.letsencrypt.org/t/beginning-issuance-from-r3/139018

Moreover 'CAfile' now defaults to @@datadir@@/lacme/ca-certificates.crt
which is a concatenation of all known active CA certificates (which
includes the previous default).
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This is a breaking change.  The certificate indicated by 'CAfile' is no
longer used as is in 'certificate-chain' (along with the leaf cert).
The chain returned by the ACME v2 endpoint is used instead.  This allows
for more flexbility with respect to key/CA rotation, cf.
https://letsencrypt.org/2020/11/06/own-two-feet.html and
https://community.letsencrypt.org/t/beginning-issuance-from-r3/139018

Moreover 'CAfile' now defaults to @@datadir@@/lacme/ca-certificates.crt
which is a concatenation of all known active CA certificates (which
includes the previous default).
</pre>
</div>
</content>
</entry>
<entry>
<title>Issue GET and POST-as-GET requests (RFC 8555 sec. 6.3)</title>
<updated>2019-08-26T10:35:58+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2019-08-21T16:55:48+00:00</published>
<link rel='alternate' type='text/html' href='http://git.guilhem.org/lacme/commit/?id=aa779d1f1658a1244e2cba03b07ea9be3c4ee2a0'/>
<id>aa779d1f1658a1244e2cba03b07ea9be3c4ee2a0</id>
<content type='text'>
For the  authorizations, order and certificate URLs.
See RFC 8555 sec. 7.1.

Let's Encrypt will remove support of unauthenticated GETs from the V2
API on 01 Nov 2019:

    https://community.letsencrypt.org/t/acme-v2-scheduled-deprecation-of-unauthenticated-resource-gets/74380
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
For the  authorizations, order and certificate URLs.
See RFC 8555 sec. 7.1.

Let's Encrypt will remove support of unauthenticated GETs from the V2
API on 01 Nov 2019:

    https://community.letsencrypt.org/t/acme-v2-scheduled-deprecation-of-unauthenticated-resource-gets/74380
</pre>
</div>
</content>
</entry>
<entry>
<title>Mention the Debian BTS in the manpages.</title>
<updated>2016-06-14T15:45:58+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-06-14T15:39:16+00:00</published>
<link rel='alternate' type='text/html' href='http://git.guilhem.org/lacme/commit/?id=955a29db14877a8374d7ef334e33a042925df418'/>
<id>955a29db14877a8374d7ef334e33a042925df418</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
