diff --git a/04-ISSUES/020-a-certificate-is-issued-and-never-collected/00-report.md b/04-ISSUES/020-a-certificate-is-issued-and-never-collected/00-report.md index 34e51fb..98c3fd8 100644 --- a/04-ISSUES/020-a-certificate-is-issued-and-never-collected/00-report.md +++ b/04-ISSUES/020-a-certificate-is-issued-and-never-collected/00-report.md @@ -58,15 +58,16 @@ may say nothing about behaviour against a public authority. | a hand-written server config | suspected, and wrong. Replacing it with the server's **own** default config, changing only the challenge port, gives the identical error | | the finalize URL being empty | the authority logs finalisation being accepted | | the challenge path | the authorisation goes valid | +| the server version | pinned 2.5.0 behaves exactly as `latest`, so the draft profiles extension is not it | ## Where it might be - **The order's `certificate` field is absent when the client reads it.** The client waits for the order to become valid and only then fetches, so an empty location on a valid order is the remaining shape. -- **A moving tag was used.** `pebble:latest` advertises a draft *profiles* extension in its - directory. A pinned older version is being tried — the third time today that not pinning a tag - cost a run. +- ~~**A moving tag was used.**~~ **Ruled out.** `pebble:latest` advertises a draft *profiles* + extension, so a pinned 2.5.0 was tried: **identical failure**. The scenario now pins it anyway, + which it should have from the start. ## Why this is filed rather than pursued