From 0617ae669671477c524437e493d92f455065955e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20M=2E=20Requena=20Plens?= Date: Thu, 10 Sep 2026 15:56:24 +0200 Subject: [PATCH] Poll the order this run created, not the one the previous cert came from (#7237) A renewal in dns manual mode writes the previous certificate again. The second invocation resumes from the domain conf, which carries Le_LinkOrder and Le_LinkCert from the last successful issuance. newOrder saves only Le_OrderFinalize, so after finalizing the new order the `[ -z "$Le_LinkOrder" ]` guard keeps the stale link, the poll reads the old order, and its certificate URL is the old certificate. The same gap breaks a first issuance in dns manual mode outright: there is no stale link to fall back on, and a finalize that answers while the order is still processing carries no Location header, so the run dies with "could not get order link location header". Save the order link where the order is created, next to Le_OrderFinalize, and drop the certificate link that belongs to the order just replaced. Fixes #7105 --- acme.sh | 3 +++ 1 file changed, 3 insertions(+) diff --git a/acme.sh b/acme.sh index d883f3e4..97147766 100755 --- a/acme.sh +++ b/acme.sh @@ -5449,6 +5449,9 @@ issue() { #for dns manual mode _savedomainconf "Le_OrderFinalize" "$Le_OrderFinalize" + #the second invocation must poll this order, not the one the previous cert came from + _savedomainconf "Le_LinkOrder" "$Le_LinkOrder" + _cleardomainconf "Le_LinkCert" _authorizations_seg="$(echo "$response" | _json_decode | _authorizations_from_order)" _debug2 _authorizations_seg "$_authorizations_seg"