Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OCSP Must Staple - Let's Encrypt - ending our support for that feature #6271

Closed
TravisWilder opened this issue Jan 28, 2025 · 2 comments
Closed

Comments

@TravisWilder
Copy link

Summary

Hi - just got an email and I did not found any changes / pulls lately on this:

The certificates for the hostnames below (issued by the Let's Encrypt account associated with this email address) use a feature called "OCSP Must Staple." We are ending our support for that feature (https://letsencrypt.org/2024/12/05/ending-ocsp), along with our support for OCSP in general, and replacing it with Certificate Revocation Lists (https://letsencrypt.org/2022/09/07/new-life-for-crls).

After May 7th, 2025, requests for certificates with "OCSP Must Staple" will fail.

To ensure your certificates continue to automatically renew, please change your ACME client configuration to not request OCSP Must Staple.

Motivation

Let's Encrypt will continue to work as the mail list all my MailCow Domains I assume the setting is set to "must staple"

Additional context

No response

@FreddleSpl0it
Copy link
Collaborator

mailcow doesn’t use OCSP Must-Staple, so no action is needed.

@TravisWilder
Copy link
Author

you are totally right - I need to excuse myself for opening the ticket.
Domains affected are NOT mailcow related - sorry

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants