Skip to content

Update dependency Certes to v4 - #1375

Open
renovate[bot] wants to merge 1 commit into
dev8from
renovate/certes-4.x
Open

renovate[bot] wants to merge 1 commit into
dev8from
renovate/certes-4.x

Conversation

@renovate

@renovate renovate Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
Certes 3.0.4 → 4.1.0 age confidence

Release Notes

fszlin/certes (Certes)

v4.1.0

Added
  • IP address identifiers (RFC 8738): IdentifierType.Ip, and NewOrder,
    NewOrderWithProfile and NewReplacementOrder overloads accepting typed
    Identifier lists. IP values are validated and sent in canonical form.
  • Certificate profile discovery through DirectoryMeta.Profiles, selection via
    NewOrderWithProfile, and the selected Order.Profile
    (#​330). Profile orders can also
    include an ARI replacement certificate ID.
  • ACME Renewal Information (ARI, RFC 9773): Directory.RenewalInfo,
    GetRenewalInfoCertificateId() for CertificateChain and IEncodable,
    GetRenewalInfo() (suggested window, explanation URL and Retry-After) and
    NewReplacementOrder() extension methods on IAcmeContext, and Order.Replaces.
    Based on the proposal in #​329
    by @​WhitWaldo.
  • CLI: order new --profile and --replaces, cert renewal-info <cert-path>,
    and the tls-alpn challenge type for order authz/order validate (with
    dns-01, http-01 and tls-alpn-01 aliases). IP addresses passed to
    order new are ordered as IP identifiers.
Changed
  • NewOrder, NewOrderWithProfile and NewReplacementOrder string overloads
    now send values that strictly parse as IP addresses as ip identifiers in
    canonical form, instead of dns. CAs reject IP addresses as DNS identifiers, so
    previously such orders always failed.
  • IOrderContext.Authorization(value, IdentifierType.Ip) compares IP identifiers
    by address rather than by text.
  • CertificationRequestBuilder encodes subject alternative names that are IP
    addresses as IP SANs instead of DNS names, and TlsAlpnCertificate does the same
    for its subject name.
  • When CsrInfo.CommonName is not set, Finalize/Generate use the first DNS
    name of at most 64 characters as the common name, instead of always the first
    identifier. IP-only orders produce a CSR without a common name.
Fixed
  • CLI: cert pfx --help described the command as exporting PEM.

Full changelog: https://github.com/fszlin/certes/blob/v4.1.0/docs/CHANGELOG.md

v4.0.0

Breaking changes
  • PFX export now encrypts the private key and certificates with AES-256-CBC
    (PBES2, PBKDF2 with HMAC-SHA256) instead of 3DES and 40-bit RC2. OpenSSL 3 and
    Android reject the old algorithms, so PFX files from earlier versions failed to
    load there without OpenSSL's legacy provider. Windows Server 2016 and earlier
    cannot read AES-encrypted PFX files; set PfxBuilder.Encryption to
    PfxEncryption.Legacy, or pass --legacy-encryption to certes cert pfx, to
    keep the old algorithms. The PFX integrity check remains HMAC-SHA1 with 1024
    iterations, because BouncyCastle does not expose other settings.
Fixed
  • IOrderContextExtensions.Generate now waits for an order to become ready
    before sending finalize. Previously it could finalize while the order was still
    pending, which ACME servers reject. The retryCount budget remains shared
    between this pre-finalize wait and post-finalize polling of pending/
    processing. If challenge validation was never triggered, this can wait up to
    60 server-directed Retry-After intervals by default.
Changed
  • CertificateChainExtensions.ToPem now always emits LF (\n) line endings,
    avoiding mixed \r\n/\n output across platforms.

Full changelog: https://github.com/fszlin/certes/blob/v4.0.0/docs/CHANGELOG.md


Configuration

📅 Schedule: (in timezone Asia/Shanghai)

  • Branch creation
    • "before 1am,before 5am,before 9am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/certes-4.x branch from ab32a08 to 3c8400d Compare September 27, 2026 17:56

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants