- Notifications
You must be signed in to change notification settings - Fork28
Releases: icing/mod_md
Releases · icing/mod_md
mod_md v2.5.2
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
- Fixed TLS-ALPN-01 challenges when multiple
MDPrivateKeys
are specified
with EC keys before RSA ones. Fixes#377. - Fixed missing newlines in the status page output. [andreasgroth]
Assets3
1 person reacted
mod_md v2.5.1
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
- When installing a custom CA file via
MDCACertificateFile
, also set the
libcurl option CURLSSLOPT_NO_REVOKE that suppresses complains by Schannel
(when curl is linked with it) about missing CRL/OCSP in certificates.
Fixes#361. - Fixed handling of corrupted httpd.json and added test 300_30 for it.
File is removed on error and written again. Fixes#369. - Added explanation in log for how to proceed when md_store.json could not be
parsed and prevented the server start.
Assets3
1 person reacted
mod_md v2.5.0
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
Assets3
1 person reacted
mod_md v2.4.31
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
- Improved error reporting when waiting for ACME server to verify domains
or finalizing the order fails, e.g. times out. - Increasing the timeouts to wait for ACME server to verify domain names
and issue the certificate from 30 seconds to 5 minutes.
Assets3
1 person reacted
mod_md v2.4.30
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
- Changed a log level from error to debug when Stapling is enabled but a certificate carries no OCSP responder URL.
Assets3
1 person reacted
v2.4.29
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
- Fixed HTTP-01 challenges to not carry a final newline, as some ACME server fail to ignore it. [Michael Kaufmann (mkauf)]
- Fixed missing label+newline in server-status plain text output when MDStapling is enabled.
Assets3
v2.4.28
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
- When the server starts, it looks for new, staged certificates to activate. If
the staged set of files in 'md/staging/' is messed up, this could
prevent further renewals to happen. Now, when the staging set is present, but
could not be activated due to an error, purge the whole directory.
Assets3
mod_md v2.4.27
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
- Fix certificate retrieval on ACME renewal to not require a 'Location:' header returned by the ACME CA. This was the way it was done in ACME before it became an IETF standard. Let's Encrypt still supports this, but other CAs do not. Refs#265.
- Restore compatibility with OpenSSL < 1.1. [ylavic]
Assets3
mod_md v2.4.26
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
- Using OCSP stapling information to trigger certificate renewals. Proposed
by Fraser Tweedale. - Added directive
MDCheckInterval
to control how often the server checks
for detected revocations. Added proposals for configurations in the
README.md chapter "Revocations". - OCSP stapling: accept OCSP responses without a
nextUpdate
entry which is
allowed in RFC 6960. Treat those as having an update interval of 12 hours.
Added by@frasertweedale. - Adapt OpenSSL usage to changes in their API. By Yann Ylavic.
mod_md v2.4.25
Compare
Could not load tags
Nothing to show
{{ refName }}defaultLoading
- Fix the reported "until" validity of a certificate in the status handler.
[Rainer Jung] - Fix possible NULL deref when logging the error that an authentication
resource could not be retrieved from the ACME server. Refs#324