Uploaded image for project: 'WildFly Elytron'
  1. WildFly Elytron
  2. ELY-1640

Update AcmeClientSpi.changeAccountKey() to no longer send the newKey once the new ACME v2 changes are in production

    XMLWordPrintable

Details

    Description

      For ELY-1629, AcmeClientSpi.changeAccountKey() was updated to include both newKey and oldKey in the inner payload for the account key change request to prepare for the ACME v2 key rollover breaking change. Currently, specifying both works fine since Let's Encrypt's staging server will expect oldKey and ignore newKey and Let's Encrypt's production server will expect newKey and ignore oldKey. However, once the new ACME v2 key rollover changes are available in Let's Encrypt's production server on Aug. 23rd, we can update this method to only include the oldKey in the inner payload.

      Attachments

        Issue Links

          Activity

            People

              fjuma1@redhat.com Farah Juma
              fjuma1@redhat.com Farah Juma
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: