Poll the order this run created, not the one the previous cert came from (#7237)

A renewal in dns manual mode writes the previous certificate again. The
second invocation resumes from the domain conf, which carries
Le_LinkOrder and Le_LinkCert from the last successful issuance. newOrder
saves only Le_OrderFinalize, so after finalizing the new order the
`[ -z "$Le_LinkOrder" ]` guard keeps the stale link, the poll reads the
old order, and its certificate URL is the old certificate.

The same gap breaks a first issuance in dns manual mode outright: there
is no stale link to fall back on, and a finalize that answers while the
order is still processing carries no Location header, so the run dies
with "could not get order link location header".

Save the order link where the order is created, next to Le_OrderFinalize,
and drop the certificate link that belongs to the order just replaced.

Fixes #7105
This commit is contained in:
José M. Requena Plens
2026-09-10 21:56:24 +08:00
committed by GitHub
Unverified
parent 75afdcc1fb
commit 0617ae6696
+3
View File
@@ -5449,6 +5449,9 @@ issue() {
#for dns manual mode
_savedomainconf "Le_OrderFinalize" "$Le_OrderFinalize"
#the second invocation must poll this order, not the one the previous cert came from
_savedomainconf "Le_LinkOrder" "$Le_LinkOrder"
_cleardomainconf "Le_LinkCert"
_authorizations_seg="$(echo "$response" | _json_decode | _authorizations_from_order)"
_debug2 _authorizations_seg "$_authorizations_seg"