#1142283 lego: Disables all third-party DNS-providers without warning

Package:
lego
Source:
lego
Description:
Let's Encrypt client
Submitter:
Michael Fladischer
Date:
2026-08-10 22:15:01 UTC
Severity:
normal
Tags:
#1142283#5
Date:
2026-07-17 06:46:56 UTC
From:
To:
Dear Maintainer,

the upload to trixie-backports silently disables all third-party DNS-01
providers. Given that most of them were available in trixie as per 4.9.1-2, this
should at least warrant a NEWS entry, so that users are warned, that existing
setups will break and leave servers without working certificates.

Regards,
fladi


- -- System Information:
Debian Release: forky/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 7.1.3+deb14-amd64 (SMP w/20 CPU threads; PREEMPT)
Kernel taint flags: TAINT_USER
Locale: LANG=en_DK.UTF-8, LC_CTYPE=en_DK.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages lego depends on:
ii  ca-certificates  20260601
ii  libc6            2.43-2

lego recommends no packages.

lego suggests no packages.
-----BEGIN PGP SIGNATURE-----

iQFPBAEBCgA5FiEEqVSlRXW87UkkCnJc/9PIi5l90WoFAmpZz+AbHGZsYWRpc2No
ZXJtaWNoYWVsQGZsYWRpLmF0AAoJEP/TyIuZfdFqJaoH/1HnHvllfmMm/5ISKOg1
8N2A+ioJctP1AjfuEYJPiSlyhDxQCM/295wyzbZSYoNfVfaOftw+ugB+lsyZ//G2
80RSdQChB/T8uJcqaRSNUGoCfEvy8WBzs+e5AzQpnoNHQ3MYSYgEAwK1W7X4C9yz
63uC3eyOR2O7m4y+inoJyh7DmsZgZhUCdv9De7sIWfQMuyjjJpmv1JHyrT2UZUaH
SJcBD94m4MHk3GyCSqkAFMSRv4Wx5Z8Y9SoDNK/S8TI9xoRhTwZJSflwkCSQb8Tb
ZY16i/t4gSi9fOkw/WKU+yh8rQCozHi53wdxN9PuxXHf44yejaxsJ3yKDXSefhMj
qIc=
=jby3
-----END PGP SIGNATURE-----

#1142283#10
Date:
2026-07-18 12:33:46 UTC
From:
To:
control: tags -1 + confirmed

  Oops, that's an accidental regression which I've fixed and will get
uploaded shortly. I didn't notice it because the build log showed all
the various DNS providers being compiled, so I thought everything was
good. :) Thanks for the report!

Mathias

#1142283#17
Date:
2026-07-18 12:48:47 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
golang-github-xenolf-lego, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142283@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mathias Gibbens <gibmat@debian.org> (supplier of updated golang-github-xenolf-lego package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 18 Jul 2026 12:27:15 +0000
Source: golang-github-xenolf-lego
Architecture: source
Version: 4.35.2-3
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Mathias Gibbens <gibmat@debian.org>
Closes: 1142283
Changes:
 golang-github-xenolf-lego (4.35.2-3) unstable; urgency=medium
 .
   * Add provider toml files to DH_GOLANG_INSTALL_EXTRA (Closes: #1142283)
Checksums-Sha1:
 a713dc77a340193be5fec9a1faf781bcbabcd949 3302 golang-github-xenolf-lego_4.35.2-3.dsc
 be17be4ab683f72c0f44ff214220e851932bcc24 1091892 golang-github-xenolf-lego_4.35.2.orig.tar.gz
 692a5ad3fecc20208a9760bf7a33529b6da94ec8 9056 golang-github-xenolf-lego_4.35.2-3.debian.tar.xz
 49e7c7e7e6b6aa7189077b793164b5a577ec1ff4 17629 golang-github-xenolf-lego_4.35.2-3_amd64.buildinfo
Checksums-Sha256:
 4303ae1b58ce671eb25569326ebdd8a8f7b4edeeb5e66ee735ea0e946ff83fe3 3302 golang-github-xenolf-lego_4.35.2-3.dsc
 0afa5397dff24643ab34773518063432ed939788435a16305c92f2090a899c3b 1091892 golang-github-xenolf-lego_4.35.2.orig.tar.gz
 f7a412f07a54253090ebcfd4c4cf500f7729a2ac22fd263b7d764ac606da7c33 9056 golang-github-xenolf-lego_4.35.2-3.debian.tar.xz
 e0e73dbd906f3c8aa4b0233a602371b790c5aabdc90d97bf945a8d51b430d005 17629 golang-github-xenolf-lego_4.35.2-3_amd64.buildinfo
Files:
 3aa5c18fac2f4e8312b90fd031409a06 3302 golang optional golang-github-xenolf-lego_4.35.2-3.dsc
 a641bc71e0185c88671e2bb5f1878108 1091892 golang optional golang-github-xenolf-lego_4.35.2.orig.tar.gz
 62177591091de2c8cab1ea3e6110a110 9056 golang optional golang-github-xenolf-lego_4.35.2-3.debian.tar.xz
 a053a4fbb82a07e917f28c7afc8f9b7e 17629 golang optional golang-github-xenolf-lego_4.35.2-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEE1Bp60H32xfynSJ8cKe7i1uz0QvkFAmpbczMSHGdpYm1hdEBk
ZWJpYW4ub3JnAAoJECnu4tbs9EL5t+oP+wVR21llEUOHoSbIyCtRo53zctT9+OHa
AyD0T201ZfXDlrdkKroQd2RVqta+ChxDCKYU7EvT8FczXdyGuzjBEFi/TKwfSgRR
0fqzwyQEFak/czxV8TIZjnuaj3FIHBTe65XmEBHPLEH+sXZPy5VI07S2wADMCul1
Efxs4S29SgX8gkXptcwNKNHO6i38rx8OpCnOv8Ri3knP8QYNcmmeLlWaquzMLl9i
4VDCDyzFeNcQYbcxistA7njo1rqnKnqEafFfUcrhngf35UB9gckwQabCcyYAtM66
A5XzyT2X2a30PHucNdQtub5NIuues7c5UJSMhrDjwSxsBsd7U2utiTYuSskt6bb5
x8JrdYoQoax1mf7D3TWsppGm7ZAXGDiVjnYqFD0xYZXkVXCz5vB9wuOU3GW5pPkG
tNyi0lzMbKtm8s907KbQfZOOL6DmEEYgZ9k/5ZVoWbsXyJswN4DrInngLVtRM7Ka
O9Iug5LM7Rm3Oot+6GCZ4FZfRv4oo9oJA3ahkTPChHTV5oZ94w1TYWMYl4xtEcBY
nGxCWUsET9/XTrPDO3xDWM13Gv+RiNJFZJM6TXs+O20RQnlsEJx0TKFfHx1DDYoI
Lq88xTbSRThgu8n2/K94KwFES34Ws8MrVS9uq8P+926jgck+j1olyumyaQfdT4BH
UscxCM7plDSf
=WYpg
-----END PGP SIGNATURE-----

#1142283#22
Date:
2026-08-10 15:55:36 UTC
From:
To:
Hi Mathias,


thanks for the upload to unstable. But there is also 4.35.2-2~bpo13+1 in
trixie-backports which is still affected by this and makes the package almost
unusable there. Could you also do a new upload to trixie-backports?

Thanks,
Michael

#1142283#27
Date:
2026-08-10 21:36:00 UTC
From:
To:
  4.35.2-3~bpo13+1 is available in trixie-backports for all
architectures, except riscv64 which is still waiting for a build. The
riscv64 buildds are quite slow, and they prioritize building pretty
much any package for unstable, stable, or experimental above backports.
But eventually the backported build for riscv64 will be built. :)

  If you're still seeing the -2~bpo13+1 version for amd64 (or another
architecture beside riscv64) make sure you've done an `apt update`
against a current mirror.

Mathias

#1142283#32
Date:
2026-08-10 22:13:13 UTC
From:
To:
I actually checked on riscv64 :-) should have just looked at
packages.debian.org.

Thanks,
Michael