From 41ee4c2a667b635a0ec43348d048b664c897166a Mon Sep 17 00:00:00 2001 From: Riddhesh Sanghvi Date: Tue, 30 Jun 2026 17:42:05 +0530 Subject: [PATCH 1/2] fix(ssl): honor updated le-mail on certificate renewal --- src/helper/Site_Letsencrypt.php | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/src/helper/Site_Letsencrypt.php b/src/helper/Site_Letsencrypt.php index 0669eaf1..61f47cc4 100644 --- a/src/helper/Site_Letsencrypt.php +++ b/src/helper/Site_Letsencrypt.php @@ -691,6 +691,9 @@ private function getOrCreateDistinguishedName( $domain, array $alternativeNames, if ( $this->repository->hasDomainDistinguishedName( $domain ) ) { $original = $this->repository->loadDomainDistinguishedName( $domain ); + // Honor an updated le-mail on renewal; fall back to stored email only when none is passed. + $email_address = ! empty( $email ) ? $email : $original->getEmailAddress(); + $distinguishedName = new DistinguishedName( $domain, $original->getCountryName(), @@ -698,7 +701,7 @@ private function getOrCreateDistinguishedName( $domain, array $alternativeNames, $original->getLocalityName(), $original->getOrganizationName(), $original->getOrganizationalUnitName(), - $original->getEmailAddress(), + $email_address, $alternativeNames ); } else { From 47bc8702e0a8c2e3862e8c57061b50d10d51986d Mon Sep 17 00:00:00 2001 From: Riddhesh Sanghvi Date: Thu, 24 Sep 2026 10:39:20 +0000 Subject: [PATCH 2/2] fix(ssl): use the caller's le-mail for renewal CSR executeRenewal() read le-mail from config.yml directly, so the email passed to request() (the runner config, including a --le-mail runtime override) was ignored on renewal while the first-request path used it. Pass it through instead. --- src/helper/Site_Letsencrypt.php | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/src/helper/Site_Letsencrypt.php b/src/helper/Site_Letsencrypt.php index 61f47cc4..80cbf0d7 100644 --- a/src/helper/Site_Letsencrypt.php +++ b/src/helper/Site_Letsencrypt.php @@ -439,7 +439,7 @@ public function request( $domain, $altNames = [], $email, $force = false ) { if ( $this->hasValidCertificate( $domain, $alternativeNames ) ) { \EE::debug( "Certificate found for $domain, executing renewal" ); - return $this->executeRenewal( $domain, $alternativeNames, $force ); + return $this->executeRenewal( $domain, $alternativeNames, $email, $force ); } \EE::debug( "No certificate found, executing first request for $domain" ); @@ -573,9 +573,10 @@ public function isRenewalNecessary( $domain ) { * * @param string $domain * @param array $alternativeNames + * @param string $email * @param bool $force */ - private function executeRenewal( $domain, array $alternativeNames, $force = false ) { + private function executeRenewal( $domain, array $alternativeNames, $email, $force = false ) { try { // Check expiration date to avoid too much renewal \EE::log( "Loading current certificate for $domain" ); @@ -615,7 +616,7 @@ private function executeRenewal( $domain, array $alternativeNames, $force = fals // Distinguished name \EE::debug( 'Loading domain distinguished name...' ); - $distinguishedName = $this->getOrCreateDistinguishedName( $domain, $alternativeNames, \EE\Utils\get_config_value( 'le-mail' ) ); + $distinguishedName = $this->getOrCreateDistinguishedName( $domain, $alternativeNames, $email ); // Order $domains = array_merge( [ $domain ], $alternativeNames );