[ext-letsencrypt]
renew-before-expiration = 45
rsa-key-size = 4096
<?xml version="1.0" encoding="UTF-8"?>
<packet>
<service-plan>
<add-plan-item>
<filter>
<name>Default Domain</name>
</filter>
<plan-item>
<name>urn:ext:letsencrypt:plan-item-sdk:keep-secured</name>
</plan-item>
</add-plan-item>
</service-plan>
</packet>
Setting |
Type |
Description |
Default value |
|---|---|---|---|
|
integer |
The size of the RSA private key, in bits. |
2048 |
|
string |
The User-Agent HTTP header. |
|
|
string |
The Let’s Encrypt website URL. |
|
|
string |
The Let’s Encrypt Policy and Legal Repository URL. |
|
(deprecated) |
integer |
The number of days before expiration when the certificate is scheduled for auto-renewal. The same setting can be used for the SSL It! extension as well. In this case, the setting for SSL It! will have higher priority over the one for Let’s Encrypt. Currently, the setting is still supported but will be deprecated from Let’s Encrypt in the future. |
30 |
|
string |
The path where certificates for third-party integration are stored. |
|
|
string |
The path to the trusted CA Root Certificates bundle. |
|
|
boolean |
Disable the cleanup of token files after a domain dispute is resolved. |
false |
|
boolean |
Log requests to the ACME server in the Plesk log. |
false |
|
boolean |
Set the default state of the “Secure the domain with Let’s Encrypt” checkbox shown when creating a new subscription, domain, or subdomain. |
false |
|
string |
The URL to Let’s Encrypt documentation about “Rate Limits”. The link is displayed in the extension’s GUI error messages when Let’s Encrypt rate limits have been exceeded. |
|
|
integer |
*The wait time in seconds between attempts to check if a domain is accessible via HTTP. |
5 |
|
integer |
*The maximum number of attempts to check if a domain is accessible via HTTP. |
10 |
|
integer |
*Timeout in seconds for checking if a domain is accessible via HTTP. If within the time defined by check-availability-timeout, no response code is received, the domain is considered to be unavailable. |
5 |
|
boolean |
When the “Keep websites secured with free SSL Certificate” option is enabled, if you set this setting to “false”, the Let’s Encrypt extension only replaces self-signed and expired SSL/TLS certificates. If you set it to “true”, the extension also replaces SSL/TLS certificates that are not trusted by any of the root certificates in the trusted CA Root Certificates bundle (see the |
false |
|
date interval |
Determines how often the Let’s Encrypt extension can send you notifications (for example, about a domain being secured with a Let’s Encrypt certificate or a Let’s Encrypt certificate being renewed). By default, the extension sends you one notification email per day. This email contains the information about all Let’s Encrypt-related events that occurred since the previous email was sent. To receive a separate email notification about each event right after it occurs, set this setting to now. |
1 day |
|
Sets usage of the common challenge directory: |
true |
|
(deprecated) |
Used as a registration email address when SSL/TLS certificates are renewed. Used only when an email address for domain registration was not saved in ModulesSettings and an email address of a domain owner was not registered. Currently, Let’s Encrypt requires an email to issue a certificate. The setting is still supported at the moment but will be deprecated in the future. |
The Administrator email |
|
|
Directory Resource URI. |
|
|
|
The ACME protocol version. |
|