Switching from certbot-dns-azure

The upstream package certbot-dns-azure (last release 2.6.1, December 2024) pins certbot<4.0. Installing it next to a current certbot makes pip downgrade certbot and acme to 3.3.0, which fails to import with pyOpenSSL 26 or newer (AttributeError: module 'OpenSSL.crypto' has no attribute 'X509Extension'). The upstream fix (#65) has been waiting for a maintainer since October 2025.

This fork is a drop-in replacement: the Python module (certbot_dns_azure), the plugin name (dns-azure), all options and the config file format are unchanged. Existing config files and renewal configurations keep working. Only the package name on PyPI differs.

Replace the package

Both packages install the same module, so replace one with the other. Run these with the pip of the environment certbot is installed in:

pip uninstall -y certbot-dns-azure
pip install -U certbot certbot-dns-azure-modern
pip install --force-reinstall --no-deps certbot-dns-azure-modern

Warning

Do not skip the -U: if the upstream package already downgraded certbot and acme to 3.3.0, installing the fork alone does not undo that. If both packages were installed, uninstalling the upstream one also deletes the module files they share; the last line puts them back. It is harmless otherwise.

Never install both packages at once. Recreating the virtual environment from scratch works as well.

Check the result with certbot --version and certbot plugins --text, see Verify the installation.

Nginx Proxy Manager

Nginx Proxy Manager 2.16.0 and later already use this fork; upgrade and recreate the container, see Nginx Proxy Manager.

Snap

The certbot-dns-azure snap in the Snap Store is published by the upstream author and still ships 2.6.1. This fork does not publish a snap. Remove the snaps first (snap remove certbot-dns-azure certbot) so their renewal timer stops, then install certbot and the plugin with pip or build the Dockerfile, see Installation.