Search K
Appearance
Appearance
Released: 2026-09-22
The ACME system is updated to allow using more ACME providers and use providers that would require an external account binding (EAB) support.
This will allow users to automatically renew even the paid certificates. All certificate authorities will need to shorten the certificate lifetime to 47 days by the year 2029. Without an automation using ACME, this would mean manually renewing the certificates every month. To help users automate certificate management, the bigger certificate authorities already support certificate renewals using ACME.
Users who could not use the free Let's Encrypt or ZeroSSL certificates due to specific requirements will now be able to use the ACME system to fully automate certificate management.

Note: In this release, the custom ACME provider can only be configured for each domain individually. In the upcoming releases we will add custom ACME provider support on the user package level. This will allow resellers or server administrators to configure the ACME provider with EAB for all owned users without disclosing the EAB credentials.
A new option acme_hidden_cert_providers in directadmin.conf file is added.
It is a comma separated list of ACME providers that should not be visible in the UI.
The default value lists all staging ACME servers. This means users who want to test things out on a staging ACME server will need adjust this configuration option to make them visible.
As part of a larger internal refactoring the "Create Administrator" page appears different visually but retains the same functionality.
The reseller creation form has been simplified and no longer includes customization options. New resellers are created with the default settings.
You can change these settings later on the Modify Reseller page. The Create and Customize button creates the reseller, then opens that page so you can customize its settings immediately.
The time when the certificate needs to be renewed used to be calculated by simply checking for the fixed amount of days before certificate expiry. This works well for certificates with a fixed lifetime but can cause problems for short-lived certificates.
This release changes the renewal time calculations to take into consideration the lifetime of the certificate (total amount of time the certificate is valid). The certificate will be renewed after it has used up a configured percentage of its lifetime.
The default configuration is to renew certificates after 65% of the certificate lifetime is used. This makes it work for certificates with different lifetimes, for example:
classic profile) are valid for 90 days. Renewal will happen after 90 * 0.65 = 58.5 days (58 days and 12 hours).tlsserver profile are valid for 45 days. Renewal will happen after 45 * 0.65 = 29.25 days (29 days and 6 hours).shortlived profile are valid for 160 hours. Renewal will happen after 160 * 0.65 = 104 hours (4 days and 8 hours).The renewal time algorithm also adds a random jitter component (up to 10% of the certificate lifetime). This makes different domains start renewing the certificates at slightly different times. The certificate renewal times will be distributed evenly over time, so there would not be spikes of mass certificate renewals on a single day.
The renewal time calculation is controlled by two new directadmin.conf options:
6.3.7-1 to 6.3.7-24.100 to 4.100.115.5.0 to 15.5.15.4.1 to 5.5.15.20.3 to 5.21.08.10.1 to 8.10.2A security vulnerability that could lead to a local privilege escalation is fixed.
Issue reported by security researcher mrfathoni.
private_html directories are no longer created removal In this release the main DirectAdmin service will stop creating private_html directories. These directories are not used in the web server configuration since DirectAdmin 1.695.
The action to migrate the existing private_html directories to be a symlink as well as the maintenance task to report exiting private_html directories are removed.
The existing private_html directory or symlink will be considered a normal user-owned file that has no special meaning for the DirectAdmin service.
tree and parent_tree actions from legacy File Manager API removal The legacy API command /CMD_FILE_MANAGER will no longer support action=tree and action=parent_tree parameters.
dnssec_keygen_algorithm and dnssec_keygen_keysize options from directadmin.conf removal The options dnssec_keygen_algorithm and dnssec_keygen_keysize are removed from the directadmin.conf file. These options were used only by the scripts/dnssec.sh when DNSSEC keys are being created for a new DNS zone.
The script will start using the ECDSAP256SHA256 keys and algorithm for all new DNS zones. Existing DNS zones will continue to use existing keys.
Support for the ECDSAP256SHA256 algorithm is mandatory by the DNSSEC standard. It uses smaller keys than the legacy RSA. A different default algorithm for new DNS zones can be configured by customizing the scripts/dnssec.sh script.