Merge pull request #10451 from certbot/candidate-5.0.0

release 5.0.0
This commit is contained in:
ohemorange
2025-09-02 12:09:12 -07:00
committed by GitHub
35 changed files with 82 additions and 44 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
setup( setup(
version=version, version=version,
+1 -1
View File
@@ -1,6 +1,6 @@
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
# We specify the minimum acme and certbot version as the current plugin # We specify the minimum acme and certbot version as the current plugin
+1 -1
View File
@@ -1,6 +1,6 @@
from setuptools import setup from setuptools import setup
version = '0.32.0.dev0' version = '5.1.0.dev0'
setup( setup(
version=version, version=version,
+1 -1
View File
@@ -1,6 +1,6 @@
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
setup( setup(
version=version, version=version,
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
# for now, do not upgrade to cloudflare>=2.20 to avoid deprecation warnings and the breaking # for now, do not upgrade to cloudflare>=2.20 to avoid deprecation warnings and the breaking
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'python-digitalocean>=1.15.0', # 1.15.0 or newer is recommended for TTL support 'python-digitalocean>=1.15.0', # 1.15.0 or newer is recommended for TTL support
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
# This version of lexicon is required to address the problem described in # This version of lexicon is required to address the problem described in
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'dns-lexicon>=3.14.1', 'dns-lexicon>=3.14.1',
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'dns-lexicon>=3.14.1', 'dns-lexicon>=3.14.1',
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'google-api-python-client>=1.6.5', 'google-api-python-client>=1.6.5',
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'dns-lexicon>=3.14.1', 'dns-lexicon>=3.14.1',
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'dns-lexicon>=3.14.1', 'dns-lexicon>=3.14.1',
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'dns-lexicon>=3.14.1', 'dns-lexicon>=3.14.1',
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'dns-lexicon>=3.15.1', 'dns-lexicon>=3.15.1',
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
# This version was chosen because it is the version packaged in RHEL 9 and Debian unstable. It # This version was chosen because it is the version packaged in RHEL 9 and Debian unstable. It
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'boto3>=1.20.34', 'boto3>=1.20.34',
+1 -1
View File
@@ -2,7 +2,7 @@ import os
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
'dns-lexicon>=3.14.1', 'dns-lexicon>=3.14.1',
+1 -1
View File
@@ -1,6 +1,6 @@
from setuptools import setup from setuptools import setup
version = '5.0.0.dev0' version = '5.1.0.dev0'
install_requires = [ install_requires = [
# We specify the minimum acme and certbot version as the current plugin # We specify the minimum acme and certbot version as the current plugin
+61
View File
@@ -4,6 +4,67 @@ Certbot adheres to [Semantic Versioning](https://semver.org/).
<!-- towncrier release notes start --> <!-- towncrier release notes start -->
## 5.0.0 - 2025-09-02
### Added
- Certbot now stores the Retry-After value given by ACME Renewal Info (ARI) so
the value can be respected across multiple Certbot runs.
([#10377](https://github.com/certbot/certbot/issues/10377))
- Added `uv` as a test dependency, and switched most `pip` invocations to `uv
pip` for faster installs.
([#10428](https://github.com/certbot/certbot/issues/10428))
### Changed
- Removed final instances of pyopenssl x509 and PKey objects
* Removed `acme.crypto_util.SSLSocket`
* Removed `acme.crypto_util.probe_sni`
([#10079](https://github.com/certbot/certbot/issues/10079),
[#10381](https://github.com/certbot/certbot/issues/10381))
- Removed a number of deprecated classes/interfaces
* Removed `acme.challenges.TLSALPN01Response`
* Removed `acme.challenges.TLSALPN01`
* Removed `acme.standalone.TLSServer`
* Removed `acme.standalone.TLSALPN01Server`
([#10274](https://github.com/certbot/certbot/issues/10274))
- certbot.ocsp.RevocationChecker.__init__ no longer accepts the parameter
`enforce_openssl_binary_usage` and always uses the cryptography Python
library for OCSP checking.
([#10291](https://github.com/certbot/certbot/issues/10291))
- Python 3.9 support was removed.
([#10389](https://github.com/certbot/certbot/issues/10389))
- Migrated most functionality from `certbot/setup.py` to
`certbot/pyproject.toml`
([#10402](https://github.com/certbot/certbot/issues/10402))
- Migrated most functionality from `setup.py` to `pyproject.toml` for acme,
certbot-apache, and certbot-nginx.
([#10417](https://github.com/certbot/certbot/issues/10417))
- Migrated most functionality from `setup.py` to `pyproject.toml` for certbot
dns plugins. ([#10425](https://github.com/certbot/certbot/issues/10425))
- Updated apache TLS configuration options based on changes to Mozilla's
intermediate configuration recommendations.
* Added `DHE-RSA-CHACHA20-POLY1305` to `SSLCipherSuite` list for better
compliance
* Configured curves using `SSLOpenSSLConfCmd` so FFDH won't be used with
OpenSSL 3.0
([#10443](https://github.com/certbot/certbot/issues/10443))
### Fixed
- certbot-apache no longer prints a warning claiming the version of OpenSSL
used by Apache is too old when we were unable determine the OpenSSL version.
([#10444](https://github.com/certbot/certbot/issues/10444))
- certbot-nginx no longer uses socket.gethostname when generating self-signed
certificates for use as a temporary step of installing certificates as it
would sometimes result in strings that are too long to be used in the common
name of a certificate. The static domain "temp-certbot-nginx.invalid" is now
used instead. ([#10447](https://github.com/certbot/certbot/issues/10447))
## 4.2.0 - 2025-08-05 ## 4.2.0 - 2025-08-05
### Added ### Added
+1 -1
View File
@@ -142,7 +142,7 @@ options:
case, and to know when to deprecate support for past case, and to know when to deprecate support for past
Python versions and flags. If you wish to hide this Python versions and flags. If you wish to hide this
information from the Let's Encrypt server, set this to information from the Let's Encrypt server, set this to
"". (default: CertbotACMEClient/4.2.0 (certbot; "". (default: CertbotACMEClient/5.0.0 (certbot;
OS_NAME OS_VERSION) Authenticator/XXX Installer/YYY OS_NAME OS_VERSION) Authenticator/XXX Installer/YYY
(SUBCOMMAND; flags: FLAGS) Py/major.minor.patchlevel). (SUBCOMMAND; flags: FLAGS) Py/major.minor.patchlevel).
The flags encoded in the user agent are: --duplicate, The flags encoded in the user agent are: --duplicate,
+1 -1
View File
@@ -1,4 +1,4 @@
"""Certbot client.""" """Certbot client."""
# version number like 1.2.3a0, must have at least 2 parts, like 1.2 # version number like 1.2.3a0, must have at least 2 parts, like 1.2
__version__ = '5.0.0.dev0' __version__ = '5.1.0.dev0'
+1 -1
View File
@@ -1,6 +1,6 @@
from setuptools import setup from setuptools import setup
version = '1.0' version = '5.1.0.dev0'
setup( setup(
version=version, version=version,
-3
View File
@@ -1,3 +0,0 @@
Removed final instances of pyopenssl x509 and PKey objects
* Removed `acme.crypto_util.SSLSocket`
* Removed `acme.crypto_util.probe_sni`
-5
View File
@@ -1,5 +0,0 @@
Removed a number of deprecated classes/interfaces
* Removed `acme.challenges.TLSALPN01Response`
* Removed `acme.challenges.TLSALPN01`
* Removed `acme.standalone.TLSServer`
* Removed `acme.standalone.TLSALPN01Server`
-1
View File
@@ -1 +0,0 @@
certbot.ocsp.RevocationChecker.__init__ no longer accepts the parameter `enforce_openssl_binary_usage` and always uses the cryptography Python library for OCSP checking.
-1
View File
@@ -1 +0,0 @@
Certbot now stores the Retry-After value given by ACME Renewal Info (ARI) so the value can be respected across multiple Certbot runs.
-3
View File
@@ -1,3 +0,0 @@
Removed final instances of pyopenssl x509 and PKey objects
* Removed `acme.crypto_util.SSLSocket`
* Removed `acme.crypto_util.probe_sni`
-1
View File
@@ -1 +0,0 @@
Python 3.9 support was removed.
-1
View File
@@ -1 +0,0 @@
Migrated most functionality from `certbot/setup.py` to `certbot/pyproject.toml`
-1
View File
@@ -1 +0,0 @@
Migrated most functionality from `setup.py` to `pyproject.toml` for acme, certbot-apache, and certbot-nginx.
-1
View File
@@ -1 +0,0 @@
Migrated most functionality from `setup.py` to `pyproject.toml` for certbot dns plugins.
-1
View File
@@ -1 +0,0 @@
Added `uv` as a test dependency, and switched most `pip` invocations to `uv pip` for faster installs.
-3
View File
@@ -1,3 +0,0 @@
Updated apache TLS configuration options based on changes to Mozilla's intermediate configuration recommendations.
* Added `DHE-RSA-CHACHA20-POLY1305` to `SSLCipherSuite` list for better compliance
* Configured curves using `SSLOpenSSLConfCmd` so FFDH won't be used with OpenSSL 3.0
-1
View File
@@ -1 +0,0 @@
certbot-apache no longer prints a warning claiming the version of OpenSSL used by Apache is too old when we were unable determine the OpenSSL version.
-1
View File
@@ -1 +0,0 @@
certbot-nginx no longer uses socket.gethostname when generating self-signed certificates for use as a temporary step of installing certificates as it would sometimes result in strings that are too long to be used in the common name of a certificate. The static domain "temp-certbot-nginx.invalid" is now used instead.