Update dependency Certes to v4 - #1375
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/certes-4.x
branch
from
September 27, 2026 17:56
ab32a08 to
3c8400d
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.0.4→4.1.0Release Notes
fszlin/certes (Certes)
v4.1.0Added
IdentifierType.Ip, andNewOrder,NewOrderWithProfileandNewReplacementOrderoverloads accepting typedIdentifierlists. IP values are validated and sent in canonical form.DirectoryMeta.Profiles, selection viaNewOrderWithProfile, and the selectedOrder.Profile(#330). Profile orders can also
include an ARI replacement certificate ID.
Directory.RenewalInfo,GetRenewalInfoCertificateId()forCertificateChainandIEncodable,GetRenewalInfo()(suggested window, explanation URL andRetry-After) andNewReplacementOrder()extension methods onIAcmeContext, andOrder.Replaces.Based on the proposal in #329
by @WhitWaldo.
order new --profileand--replaces,cert renewal-info <cert-path>,and the
tls-alpnchallenge type fororder authz/order validate(withdns-01,http-01andtls-alpn-01aliases). IP addresses passed toorder neware ordered as IP identifiers.Changed
NewOrder,NewOrderWithProfileandNewReplacementOrderstring overloadsnow send values that strictly parse as IP addresses as
ipidentifiers incanonical form, instead of
dns. CAs reject IP addresses as DNS identifiers, sopreviously such orders always failed.
IOrderContext.Authorization(value, IdentifierType.Ip)compares IP identifiersby address rather than by text.
CertificationRequestBuilderencodes subject alternative names that are IPaddresses as IP SANs instead of DNS names, and
TlsAlpnCertificatedoes the samefor its subject name.
CsrInfo.CommonNameis not set,Finalize/Generateuse the first DNSname of at most 64 characters as the common name, instead of always the first
identifier. IP-only orders produce a CSR without a common name.
Fixed
cert pfx --helpdescribed the command as exporting PEM.Full changelog: https://github.com/fszlin/certes/blob/v4.1.0/docs/CHANGELOG.md
v4.0.0Breaking changes
(PBES2, PBKDF2 with HMAC-SHA256) instead of 3DES and 40-bit RC2. OpenSSL 3 and
Android reject the old algorithms, so PFX files from earlier versions failed to
load there without OpenSSL's legacy provider. Windows Server 2016 and earlier
cannot read AES-encrypted PFX files; set
PfxBuilder.EncryptiontoPfxEncryption.Legacy, or pass--legacy-encryptiontocertes cert pfx, tokeep the old algorithms. The PFX integrity check remains HMAC-SHA1 with 1024
iterations, because BouncyCastle does not expose other settings.
Fixed
IOrderContextExtensions.Generatenow waits for an order to becomereadybefore sending finalize. Previously it could finalize while the order was still
pending, which ACME servers reject. TheretryCountbudget remains sharedbetween this pre-finalize wait and post-finalize polling of
pending/processing. If challenge validation was never triggered, this can wait up to60 server-directed
Retry-Afterintervals by default.Changed
CertificateChainExtensions.ToPemnow always emits LF (\n) line endings,avoiding mixed
\r\n/\noutput across platforms.Full changelog: https://github.com/fszlin/certes/blob/v4.0.0/docs/CHANGELOG.md
Configuration
📅 Schedule: (in timezone Asia/Shanghai)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.