• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

letsencrypt / pebble
9%
master: 8%

Build:
Build:
LAST BUILD BRANCH: main
DEFAULT BRANCH: master
Repo Added 26 Feb 2019 04:54PM UTC
Files 18
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH main
branch: SELECT
CHANGE BRANCH
x
  • No branch selected
  • account-challgne-00
  • add-dns-persist-support
  • add-dns-persist-support-part-2
  • already-replaced
  • ari-override
  • ari-response-type
  • ari-truncate
  • better-release
  • certid-normalize-serial
  • challtestsrv-log-less
  • cpu-custom-redirect-status-code
  • cpu-docker-use-go12
  • cpu-fix-cname-clear
  • cpu-fix-keyrollover-err-check
  • cpu-go-1-13
  • cpu-go-1-13-now
  • cpu-go-go-speed-racer
  • cpu-go12
  • cpu-mention-non-default-ports
  • cpu-mock-servfail
  • cpu-no-account-id-field-marshal
  • cpu-no-clock-dep
  • cpu-no-pebble-client
  • cpu-pag-dir-and-nonce
  • cpu-readme-subprobs
  • cpu-repo-normalize
  • cpu-stricter-than-your-gradeschool-teacher
  • cpu-tls-one-three
  • cpu-use-latest-docker
  • crl-handler
  • crl-serving-and-tests
  • crl-signing
  • dependabot/go_modules/github.com/go-jose/go-jose/v4-4.0.5
  • dependabot/go_modules/github.com/go-jose/go-jose/v4-4.1.4
  • dependabot/go_modules/github.com/miekg/dns-1.1.25
  • dependabot/go_modules/golang.org/x/crypto-0.35.0
  • dependabot/go_modules/golang.org/x/net-0.36.0
  • dependabot/go_modules/golang.org/x/net-0.38.0
  • dependabot/go_modules/golang.org/x/net-0.55.0
  • dns-persist-01
  • dont-update-absent-parent-order
  • ecdsa-chains
  • feat/update-workflows
  • fix-akid_certs
  • fix-ci
  • fix-lints-ci
  • fix-order-recursive-rlock
  • http-chunked-encoded-requests
  • inahga/zizmor
  • invalid-profile
  • jit-persost
  • main
  • master
  • mattm-deps
  • mattm-go-jose
  • mattm-go-jose-4.1.3
  • mattm-golangci-lint-2
  • mattm-golangcilint
  • mattm-golangcilint-2.9.0
  • mldsa-chains
  • newcert
  • no-finalize-loc
  • optional-comments-pr536
  • order-for-display-race
  • orders-not-deactivated
  • parseTimeAlgoCheck
  • patch-1
  • paul.wouters-Rcode-fix
  • pzduniak/fips-safe-ski
  • rand-seed
  • reason-code-allowlist
  • replace-docker-login-action
  • revocation-race-fix
  • revoked-duplicate
  • sslkeylog
  • tcp-retry
  • test-cpu-go-go-speed-racer
  • update-dns-account-01
  • user-action
  • useragent
  • v2.0.1
  • v2.0.2
  • v2.1.0
  • v2.2.0
  • v2.2.1
  • v2.2.2
  • v2.3.0
  • v2.3.1
  • vancluever-profile-default-promote

28 Sep 2026 08:14PM UTC coverage: 9.477% (+0.2%) from 9.243%
36477763631

push

github

web-flow
Normalize the serial in NewCertID so ARI replaces lookups match (#556)

When a certificate's serial starts with a byte >= 0x80, ACME clients put
an extra `00` in front of it in the ARI certID. That's correct, since
RFC 9773 asks for the DER integer bytes. But Pebble stores issued
certificates under the serial without that `00`, so a new order with
`replaces` for one of those certificates can't find the original and
fails with a 500. This happens for about 1 in 256 certificates.

The fix builds the certID's lookup key from the parsed number instead of
the raw bytes, so both forms give the same key. This is the same way the
certificate is stored in `ca.go`, and the renewalInfo endpoint already
looks things up this way.

Fixes https://github.com/letsencrypt/pebble/issues/550

3 of 3 new or added lines in 1 file covered. (100.0%)

442 of 4664 relevant lines covered (9.48%)

1.71 hits per line

Relevant lines Covered
Build:
Build:
4664 RELEVANT LINES 442 COVERED LINES
1.71 HITS PER LINE
Source Files on master
  • Tree
  • List 18
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
36477763631 main Normalize the serial in NewCertID so ARI replaces lookups match (#556) When a certificate's serial starts with a byte >= 0x80, ACME clients put an extra `00` in front of it in the ARI certID. That's correct, since RFC 9773 asks for the DER intege... push 28 Sep 2026 08:15PM UTC web-flow github
9.48
36292524459 crl-serving-and-tests Serve a CRL when configured, and test it in CI Add the crlListenAddress, crlBaseURL, crlMaxDelay and crlValidity config fields and their PEBBLE_CRL_* environment overrides. When both the listen address and base URL are set, Pebble serves its CRL ... Pull #562 27 Sep 2026 03:50AM UTC Preston12321 github
14.25
36292428832 crl-handler wfe: Add a CRL handler and record when revocations reach the CRL Add CRLHandler, which serves a freshly signed CRL at the CA's CRL URL, and set CRLVisibleAt on revoked certificates so that revocations appear on the CRL after a random delay. The ... Pull #561 27 Sep 2026 03:48AM UTC Preston12321 github
13.2
36292344234 crl-signing ca: Add support for building and signing a CRL Add an optional CRLConfig to the CA. When it's set, issued certificates include a CRL Distribution Point, and GetCRL returns a CRL signed by the leaf-issuing intermediate with every revoked certifica... Pull #560 27 Sep 2026 03:46AM UTC Preston12321 github
12.73
36292204789 reason-code-allowlist Only accept revocation reasons 0, 1, 3, 4, 5 and 9 Replace the check for reasons 7 and >10 with an allowlist. This also rejects cACompromise (2), which applies only to CA certificates; certificateHold (6), which the Baseline Requirements forbid; ... Pull #558 27 Sep 2026 03:43AM UTC Preston12321 github
11.54
36283887341 revocation-race-fix Fix race condition in db.MemoryStore.RevokeCertificate() Pull #557 27 Sep 2026 12:54AM UTC Preston12321 github
11.46
35880095069 certid-normalize-serial Normalize the serial in NewCertID so ARI replaces lookups match ARI certIDs carry the serial as DER INTEGER value bytes, which include a leading 0x00 when the top bit is set. Issued certificates are indexed by the hex of big.Int.Bytes(), which ha... Pull #556 23 Sep 2026 04:00PM UTC shyney7 github
9.48
35784676080 main Use RFC 7093 SHA-512 truncated SKIs (#551) Always generate Subject Key Identifiers according to RFC 7093 Section 2 method 3: the leftmost 160 bits of the SHA-512 hash of the `subjectPublicKey` BIT STRING. This removes Pebble's use of SHA-1, so i... push 22 Sep 2026 09:08PM UTC web-flow github
9.24
35781538068 pzduniak/fips-safe-ski Use crypto/ecdh to parse the RFC 7093 example key elliptic.Unmarshal is deprecated since Go 1.21 and fails staticcheck SA1019. Co-authored-by: Cursor <cursoragent@cursor.com> Pull #551 22 Sep 2026 09:02PM UTC pzduniak github
9.24
35759968840 main Fix deadlock from recursive RLock in Order() (#555) orderForDisplay takes a lock because many of its other callers don't take a lock themselves, but it leads to a recursive lock in this case. The only reason that Order() takes a lock at all is in... push 22 Sep 2026 05:20PM UTC web-flow github
9.24
See All Builds (1503)
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc