Do not poll /acme/issuer-cert when generating LetsEncrypt TLS certificates
From LetsEncrypt:
Hi,
As part of our due diligence prior to shutting down the ACME v2 API's /acme/issuer-cert endpoint, we detected that an ACME v2 client with useragent
ansible-httpget
and associated with contact addresspaddatrapper@debian.org
appears to poll the endpoint in between issuances.For example, we saw the client complete an issuance for
jitsi-sandbox.video.fosdem.org
on 2020-12-07 at 07:38 UTC, then poll the issuer-cert endpoint 13 times over the next ~36 hours, then begin another issuance forvogol-sandbox.video.fosdem.org
on 2020-12-08 at 20:37 UTC.Yours appears to be the only client exhibiting this behavior, so we assume you have something custom running. Please update your client to not query the /acme/issuer-cert endpoint before we remove it on Thursday, Jan 7, 2021.
More information can be found here: https://community.letsencrypt.org/t/acme-v2-removing-acme-issuer-cert-endpoint/140382
Thank you, Aaron, on behalf of Let's Encrypt
I am not sure if this was due to the network connectivity issues we were encountering or something with our LetsEncrypt role