Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #228751 > unrolled thread

Certbot in Buster

Started byPhilipp Ewald <philipp.ewald@digionline.de>
First post2020-11-18 12:50 +0100
Last post2020-11-24 17:30 +0100
Articles 10 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  Certbot in Buster Philipp Ewald <philipp.ewald@digionline.de> - 2020-11-18 12:50 +0100
    Re: Certbot in Buster Michael Stone <mstone@debian.org> - 2020-11-18 15:30 +0100
    Re: Certbot in Buster Andrei POPESCU <andreimpopescu@gmail.com> - 2020-11-18 15:40 +0100
      Re: Certbot in Buster Philipp Ewald <philipp.ewald@digionline.de> - 2020-11-18 18:50 +0100
        Re: Certbot in Buster Michael Stone <mstone@debian.org> - 2020-11-18 19:10 +0100
          Re: Certbot in Buster Andrei POPESCU <andreimpopescu@gmail.com> - 2020-11-19 08:20 +0100
            Re: Certbot in Buster Michael Stone <mstone@debian.org> - 2020-11-19 14:40 +0100
              Re: Certbot in Buster David Wright <deblis@lionunicorn.co.uk> - 2020-11-19 21:50 +0100
          Re: Certbot in Buster Philipp Ewald <philipp.ewald@digionline.de> - 2020-11-24 17:20 +0100
            Re: Certbot in Buster Michael Stone <mstone@debian.org> - 2020-11-24 17:30 +0100

#228751 — Certbot in Buster

FromPhilipp Ewald <philipp.ewald@digionline.de>
Date2020-11-18 12:50 +0100
SubjectCertbot in Buster
Message-ID<Bcu8i-4yB-7@gated-at.bofh.it>
Hello,

https://community.letsencrypt.org/t/certbot-users-preparing-for-the-isrg-root-transition-january-11-2021/138059

certbot is on Version 0.31.0 in Debian Buster.


> As of January 11, 2021, we’re planning to make a change to our API so that ACME clients will, by default, serve a certificate chain that leads to ISRG Root X

This would be bad for older Android devises. To use the old Intermediate certificate its needet to use certbot Version 1.6.0 or higher. But this Version is only avalible in Debian sid/buster-backports

I have allready ask the Maintainer to update the certbot package but no answer.


What can i do?


Kind regards
Philipp
  
-- 
Philipp Ewald
Administrator

DigiOnline GmbH, Probsteigasse 15 - 19, 50670 Köln
Fax: +49 221 6500-690, E-Mail: philipp.ewald@digionline.de

AG Köln HRB 27711, St.-Nr. 5215 5811 0640
Geschäftsführer: Werner Grafenhain

Informationen zum Datenschutz: www.digionline.de/ds

[toc] | [next] | [standalone]


#228755

FromMichael Stone <mstone@debian.org>
Date2020-11-18 15:30 +0100
Message-ID<BcwD8-655-5@gated-at.bofh.it>
In reply to#228751
On Wed, Nov 18, 2020 at 12:44:57PM +0100, Philipp Ewald wrote:
>Hello,
>
>https://community.letsencrypt.org/t/certbot-users-preparing-for-the-isrg-root-transition-january-11-2021/138059
>
>certbot is on Version 0.31.0 in Debian Buster.
>
>
>>As of January 11, 2021, we’re planning to make a change to our API so that ACME clients will, by default, serve a certificate chain that leads to ISRG Root X
>
>This would be bad for older Android devises. To use the old Intermediate certificate its needet to use certbot Version 1.6.0 or higher. But this Version is only avalible in Debian sid/buster-backports
>
>I have allready ask the Maintainer to update the certbot package but no answer.
>
>
>What can i do?

Have you tried just installing the sid version? I haven't looked really 
closely but at least at the top it looks like an arch:all package with 
few versioned dependencies.

[toc] | [prev] | [next] | [standalone]


#228756

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2020-11-18 15:40 +0100
Message-ID<BcwMO-685-11@gated-at.bofh.it>
In reply to#228751

[Multipart message — attachments visible in raw view] — view raw

On Mi, 18 nov 20, 12:44:57, Philipp Ewald wrote:
> Hello,
> 
> https://community.letsencrypt.org/t/certbot-users-preparing-for-the-isrg-root-transition-january-11-2021/138059
> 
> certbot is on Version 0.31.0 in Debian Buster.
> 
> 
> > As of January 11, 2021, we’re planning to make a change to our API so that ACME clients will, by default, serve a certificate chain that leads to ISRG Root X

If the package in stable is still usable afterwards (even if with 
reduced functionality) this looks like a case for backports.

> This would be bad for older Android devises. To use the old 
> Intermediate certificate its needet to use certbot Version 1.6.0 or 
> higher. But this Version is only avalible in Debian 
> sid/buster-backports
 
According to 'rmadison certbot' a newer version is only available in 
testing and unstable, but not in buster-backports:

    certbot    | 0.28.0-1~bpo9+1 | stretch-backports | all
    certbot    | 0.28.0-1~deb9u2 | oldstable         | all
    certbot    | 0.31.0-1        | stable            | all
    certbot    | 1.8.0-1         | testing           | all
    certbot    | 1.8.0-1         | unstable          | all


> I have allready ask the Maintainer to update the certbot package but no answer.

I presume you did this via direct e-mail only.

> What can i do?

Write an e-mail to debian-backports with Cc: the package Maintainer 
asking nicely for a backport.

Preferably you should be using <package-name>@packages.debian.org as 
this might reach more people (e.g. others interested in the package), 
just in case the Maintainer won't provide a backport or is unresponsive.

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#228761

FromPhilipp Ewald <philipp.ewald@digionline.de>
Date2020-11-18 18:50 +0100
Message-ID<BczKG-7R2-7@gated-at.bofh.it>
In reply to#228756
> According to 'rmadison certbot' a newer version is only available in
> testing and unstable, but not in buster-backports:

Oh my mistake

> I presume you did this via direct e-mail only.

exactly... from packages.debian.org :)
  
  
> Preferably you should be using <package-name>@packages.debian.org as
> this might reach more people (e.g. others interested in the package),
> just in case the Maintainer won't provide a backport or is unresponsive.

I have done this. Many Thanks!

I hope there will be a backports.


If not:

can i install the package from unstable and after that i remove the entry in sourses.list?
or is this risky?



On 11/18/20 3:38 PM, Andrei POPESCU wrote:
> If the package in stable is still usable afterwards (even if with
> reduced functionality) this looks like a case for backports.
> 
>   
> According to 'rmadison certbot' a newer version is only available in
> testing and unstable, but not in buster-backports:
> 
>      certbot    | 0.28.0-1~bpo9+1 | stretch-backports | all
>      certbot    | 0.28.0-1~deb9u2 | oldstable         | all
>      certbot    | 0.31.0-1        | stable            | all
>      certbot    | 1.8.0-1         | testing           | all
>      certbot    | 1.8.0-1         | unstable          | all
> 
> 
>> I have allready ask the Maintainer to update the certbot package but no answer.
> 
> I presume you did this via direct e-mail only.
> 
>> What can i do?
> 
> Write an e-mail to debian-backports with Cc: the package Maintainer
> asking nicely for a backport.
> 
> Preferably you should be using <package-name>@packages.debian.org as
> this might reach more people (e.g. others interested in the package),
> just in case the Maintainer won't provide a backport or is unresponsive.
> 
> Kind regards,
> Andrei
> 

-- 
Philipp Ewald
Administrator

DigiOnline GmbH, Probsteigasse 15 - 19, 50670 Köln
Fax: +49 221 6500-690, E-Mail: philipp.ewald@digionline.de

AG Köln HRB 27711, St.-Nr. 5215 5811 0640
Geschäftsführer: Werner Grafenhain

Informationen zum Datenschutz: www.digionline.de/ds

[toc] | [prev] | [next] | [standalone]


#228763

FromMichael Stone <mstone@debian.org>
Date2020-11-18 19:10 +0100
Message-ID<BcA41-8dd-5@gated-at.bofh.it>
In reply to#228761
On Wed, Nov 18, 2020 at 06:42:27PM +0100, Philipp Ewald wrote:
>can i install the package from unstable and after that i remove the entry in sourses.list?
>or is this risky?

I wouldn't do that, just download the appropiate debs from 

http://ftp.us.debian.org/debian/pool/main/p/python-certbot/certbot_1.8.0-1_all.deb
http://ftp.us.debian.org/debian/pool/main/p/python-certbot/python3-certbot_1.8.0-1_all.deb
http://ftp.us.debian.org/debian/pool/main/p/python-acme/python3-acme_1.8.0-1_all.deb

run
  sudo dpkg -i *.deb
then
  sudo apt --fix-broken install
to clean up any dangling dependencies

You can find which debs to download by looking at
https://packages.debian.org/bullseye/certbot

Most of the dependencies are provided in buster already, except for the 
proper versions of python3-certbot and python3-acme. If you were to 
install only the certbot deb and then run apt install (without 
--fix-broken) you'd see something like this:

# apt install
Reading package lists... Done
Building dependency tree       
Reading state information... Done
You might want to run 'apt --fix-broken install' to correct these.
The following packages have unmet dependencies:
 certbot : Depends: python3-certbot (= 1.8.0-1) but it is not installed
E: Unmet dependencies. Try 'apt --fix-broken install' with no packages 
(or specify a solution).

which indicates that a particular version of the python3-certbot package 
is required. If you were to run with --fix-broken in this case instead 
of manually installing the deb linked above it would tell you that it is 
removing certbot, because the appropriate version can't be found in 
buster.

[toc] | [prev] | [next] | [standalone]


#228773

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2020-11-19 08:20 +0100
Message-ID<BcMox-75W-1@gated-at.bofh.it>
In reply to#228763

[Multipart message — attachments visible in raw view] — view raw

On Mi, 18 nov 20, 13:01:46, Michael Stone wrote:
> On Wed, Nov 18, 2020 at 06:42:27PM +0100, Philipp Ewald wrote:
> > can i install the package from unstable and after that i remove the entry in sourses.list?
> > or is this risky?
> 
> I wouldn't do that, just download the appropiate debs from
> 
> http://ftp.us.debian.org/debian/pool/main/p/python-certbot/certbot_1.8.0-1_all.deb
> http://ftp.us.debian.org/debian/pool/main/p/python-certbot/python3-certbot_1.8.0-1_all.deb
> http://ftp.us.debian.org/debian/pool/main/p/python-acme/python3-acme_1.8.0-1_all.deb

Agreed.
 
> run
>  sudo dpkg -i *.deb
> then
>  sudo apt --fix-broken install
> to clean up any dangling dependencies

It might work also to just run (with sudo as needed):

    apt install ./*.deb


Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#228775

FromMichael Stone <mstone@debian.org>
Date2020-11-19 14:40 +0100
Message-ID<BcSki-2br-11@gated-at.bofh.it>
In reply to#228773
On Thu, Nov 19, 2020 at 09:11:10AM +0200, Andrei POPESCU wrote:
>On Mi, 18 nov 20, 13:01:46, Michael Stone wrote:
>> On Wed, Nov 18, 2020 at 06:42:27PM +0100, Philipp Ewald wrote:
>> > can i install the package from unstable and after that i remove the entry in sourses.list?
>> > or is this risky?
>>
>> I wouldn't do that, just download the appropiate debs from
>>
>> http://ftp.us.debian.org/debian/pool/main/p/python-certbot/certbot_1.8.0-1_all.deb
>> http://ftp.us.debian.org/debian/pool/main/p/python-certbot/python3-certbot_1.8.0-1_all.deb
>> http://ftp.us.debian.org/debian/pool/main/p/python-acme/python3-acme_1.8.0-1_all.deb
>
>Agreed.
>
>> run
>>  sudo dpkg -i *.deb
>> then
>>  sudo apt --fix-broken install
>> to clean up any dangling dependencies
>
>It might work also to just run (with sudo as needed):
>
>    apt install ./*.deb

yes! I thought there was a way to specify a deb but the man page was no 
help and I never use apt for that myself. :) So do it that way and the 
dependencies will be handled in one step.

[toc] | [prev] | [next] | [standalone]


#228783

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2020-11-19 21:50 +0100
Message-ID<BcZ2q-6iK-5@gated-at.bofh.it>
In reply to#228775
On Thu 19 Nov 2020 at 08:34:24 (-0500), Michael Stone wrote:
> On Thu, Nov 19, 2020 at 09:11:10AM +0200, Andrei POPESCU wrote:
> > On Mi, 18 nov 20, 13:01:46, Michael Stone wrote:
> > > On Wed, Nov 18, 2020 at 06:42:27PM +0100, Philipp Ewald wrote:
> > > > can i install the package from unstable and after that i remove the entry in sourses.list?
> > > > or is this risky?
> > > 
> > > I wouldn't do that, just download the appropiate debs from
> > > 
> > > http://ftp.us.debian.org/debian/pool/main/p/python-certbot/certbot_1.8.0-1_all.deb
> > > http://ftp.us.debian.org/debian/pool/main/p/python-certbot/python3-certbot_1.8.0-1_all.deb
> > > http://ftp.us.debian.org/debian/pool/main/p/python-acme/python3-acme_1.8.0-1_all.deb
> > 
> > Agreed.
> > 
> > > run
> > >  sudo dpkg -i *.deb
> > > then
> > >  sudo apt --fix-broken install
> > > to clean up any dangling dependencies
> > 
> > It might work also to just run (with sudo as needed):
> > 
> >    apt install ./*.deb
> 
> yes! I thought there was a way to specify a deb but the man page was
> no help and I never use apt for that myself. :) So do it that way and
> the dependencies will be handled in one step.

I think the only mention of this I've seen (apart from debian-user)
is in /usr/share/doc/apt/changelog.gz where there is

  apt (1.3~pre3) unstable; urgency=medium

    […]

    [ David Kalnischkies ]
    […]
    * support "install ./foo.changes"

    […]

   -- Julian Andres Klode <jak@debian.org>  Thu, 04 Aug 2016 10:23:49 +0200

I have noticed that the sometimes unintended patterns discussed in
https://lists.debian.org/debian-user/2018/08/msg01077.html
are being eliminated in bullseye, in favour of a formal aptitude-like
syntax. No word AFAICT on install ./foo.deb, ../foo.deb, /foo.deb etc.

As I wrote before, I don't know why they didn't use a commandline
option like   install -f foo.deb   to indicate installing a file
rather than a package.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#229013

FromPhilipp Ewald <philipp.ewald@digionline.de>
Date2020-11-24 17:20 +0100
Message-ID<BeJcR-4Rz-9@gated-at.bofh.it>
In reply to#228763
Many thank! i had now finely the time to test this.... (as far as possible) last test is when Lets Encrypt change there Chain.

(security)update i have to install manual?



On 11/18/20 7:01 PM, Michael Stone wrote:
> On Wed, Nov 18, 2020 at 06:42:27PM +0100, Philipp Ewald wrote:
>> can i install the package from unstable and after that i remove the entry in sourses.list?
>> or is this risky?
> 
> I wouldn't do that, just download the appropiate debs from
> http://ftp.us.debian.org/debian/pool/main/p/python-certbot/certbot_1.8.0-1_all.deb
> http://ftp.us.debian.org/debian/pool/main/p/python-certbot/python3-certbot_1.8.0-1_all.deb
> http://ftp.us.debian.org/debian/pool/main/p/python-acme/python3-acme_1.8.0-1_all.deb
> 
> run
>   sudo dpkg -i *.deb
> then
>   sudo apt --fix-broken install
> to clean up any dangling dependencies
> 
> You can find which debs to download by looking at
> https://packages.debian.org/bullseye/certbot
> 
> Most of the dependencies are provided in buster already, except for the proper versions of python3-certbot and python3-acme. If you were to install only the certbot deb and then run apt install (without --fix-broken) you'd see something like this:
> 
> # apt install
> Reading package lists... Done
> Building dependency tree Reading state information... Done
> You might want to run 'apt --fix-broken install' to correct these.
> The following packages have unmet dependencies:
> certbot : Depends: python3-certbot (= 1.8.0-1) but it is not installed
> E: Unmet dependencies. Try 'apt --fix-broken install' with no packages (or specify a solution).
> 
> which indicates that a particular version of the python3-certbot package is required. If you were to run with --fix-broken in this case instead of manually installing the deb linked above it would tell you that it is removing certbot, because the appropriate version can't be found in buster.
> 

-- 
Philipp Ewald
Administrator

DigiOnline GmbH, Probsteigasse 15 - 19, 50670 Köln
Fax: +49 221 6500-690, E-Mail: philipp.ewald@digionline.de

AG Köln HRB 27711, St.-Nr. 5215 5811 0640
Geschäftsführer: Werner Grafenhain

Informationen zum Datenschutz: www.digionline.de/ds

[toc] | [prev] | [next] | [standalone]


#229016

FromMichael Stone <mstone@debian.org>
Date2020-11-24 17:30 +0100
Message-ID<BeJmy-4UN-5@gated-at.bofh.it>
In reply to#229013
On Tue, Nov 24, 2020 at 05:17:08PM +0100, Philipp Ewald wrote:
>(security)update i have to install manual?

yes

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web