all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
To: pbs-devel@lists.proxmox.com
Subject: [PATCH proxmox 2/2] acme-api: support HTTP proxies
Date: Thu,  8 Oct 2026 17:33:20 +0200	[thread overview]
Message-ID: <20261008153323.293158-3-s.rufinatscha@proxmox.com> (raw)
In-Reply-To: <20261008153323.293158-1-s.rufinatscha@proxmox.com>

Accept an optional proxy configuration for operations that contact
the ACME server and pass it to each new client.

Signed-off-by: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
---
 proxmox-acme-api/Cargo.toml                 |  2 ++
 proxmox-acme-api/src/account_api_impl.rs    | 27 +++++++++++++++------
 proxmox-acme-api/src/account_config.rs      |  5 ++--
 proxmox-acme-api/src/certificate_helpers.rs | 12 ++++++---
 4 files changed, 34 insertions(+), 12 deletions(-)

diff --git a/proxmox-acme-api/Cargo.toml b/proxmox-acme-api/Cargo.toml
index 4bb1720b..9229d4ea 100644
--- a/proxmox-acme-api/Cargo.toml
+++ b/proxmox-acme-api/Cargo.toml
@@ -30,6 +30,7 @@ openssl = { workspace = true, optional = true }
 proxmox-acme = { workspace = true, features = ["api-types"] }
 proxmox-base64 = { workspace = true, optional = true }
 proxmox-config-digest = { workspace = true, optional = true }
+proxmox-http = { workspace = true, optional = true }
 proxmox-log = { workspace = true, optional = true }
 proxmox-product-config = { workspace = true, optional = true }
 proxmox-rest-server = { workspace = true, optional = true }
@@ -57,6 +58,7 @@ impl = [
 
     "dep:proxmox-base64",
     "dep:proxmox-config-digest",
+    "dep:proxmox-http",
     "dep:proxmox-log",
     "dep:proxmox-product-config",
     "dep:proxmox-rest-server",
diff --git a/proxmox-acme-api/src/account_api_impl.rs b/proxmox-acme-api/src/account_api_impl.rs
index ef195908..d42a475f 100644
--- a/proxmox-acme-api/src/account_api_impl.rs
+++ b/proxmox-acme-api/src/account_api_impl.rs
@@ -7,6 +7,7 @@ use serde_json::json;
 
 use proxmox_acme::async_client::AcmeClient;
 use proxmox_acme::types::AccountData as AcmeAccountData;
+use proxmox_http::ProxyConfig;
 use proxmox_log::warn;
 
 use crate::account_config::AccountData;
@@ -41,9 +42,12 @@ pub async fn get_account(account_name: AcmeAccountName) -> Result<AccountInfo, E
     })
 }
 
-pub async fn get_tos(directory: Option<String>) -> Result<Option<String>, Error> {
+pub async fn get_tos(
+    directory: Option<String>,
+    proxy_config: Option<ProxyConfig>,
+) -> Result<Option<String>, Error> {
     let directory = directory.unwrap_or_else(|| DEFAULT_ACME_DIRECTORY_ENTRY.url.to_string());
-    Ok(AcmeClient::new(directory)
+    Ok(AcmeClient::with_proxy(directory, proxy_config)
         .terms_of_service_url()
         .await?
         .map(str::to_owned))
@@ -55,11 +59,12 @@ pub async fn register_account(
     tos_url: Option<String>,
     directory_url: Option<String>,
     eab_creds: Option<(String, String)>,
+    proxy_config: Option<ProxyConfig>,
 ) -> Result<String, Error> {
     let directory_url =
         directory_url.unwrap_or_else(|| DEFAULT_ACME_DIRECTORY_ENTRY.url.to_string());
 
-    let mut client = AcmeClient::new(directory_url.clone());
+    let mut client = AcmeClient::with_proxy(directory_url.clone(), proxy_config);
 
     let contact = account_contact_from_string(&contact);
     let account = client
@@ -73,9 +78,13 @@ pub async fn register_account(
     Ok(account.location)
 }
 
-pub async fn deactivate_account(name: &AcmeAccountName, force: bool) -> Result<(), Error> {
+pub async fn deactivate_account(
+    name: &AcmeAccountName,
+    force: bool,
+    proxy_config: Option<ProxyConfig>,
+) -> Result<(), Error> {
     let mut account_data = super::account_config::load_account_config(name).await?;
-    let mut client = account_data.client();
+    let mut client = account_data.client(proxy_config);
 
     match client
         .update_account(&json!({"status": "deactivated"}))
@@ -99,9 +108,13 @@ pub async fn deactivate_account(name: &AcmeAccountName, force: bool) -> Result<(
     Ok(())
 }
 
-pub async fn update_account(name: &AcmeAccountName, contact: Option<String>) -> Result<(), Error> {
+pub async fn update_account(
+    name: &AcmeAccountName,
+    contact: Option<String>,
+    proxy_config: Option<ProxyConfig>,
+) -> Result<(), Error> {
     let mut account_data = super::account_config::load_account_config(name).await?;
-    let mut client = account_data.client();
+    let mut client = account_data.client(proxy_config);
 
     let data = match contact {
         Some(contact) => json!({
diff --git a/proxmox-acme-api/src/account_config.rs b/proxmox-acme-api/src/account_config.rs
index ce128c45..387f002c 100644
--- a/proxmox-acme-api/src/account_config.rs
+++ b/proxmox-acme-api/src/account_config.rs
@@ -8,6 +8,7 @@ use std::path::{Path, PathBuf};
 use anyhow::{Error, bail, format_err};
 use serde::{Deserialize, Serialize};
 
+use proxmox_http::ProxyConfig;
 use proxmox_product_config::replace_secret_config;
 use proxmox_sys::error::SysError;
 
@@ -68,8 +69,8 @@ impl AccountData {
         }
     }
 
-    pub fn client(&self) -> AcmeClient {
-        let mut client = AcmeClient::new(self.directory_url.clone());
+    pub fn client(&self, proxy_config: Option<ProxyConfig>) -> AcmeClient {
+        let mut client = AcmeClient::with_proxy(self.directory_url.clone(), proxy_config);
         client.set_account(Account {
             location: self.location.clone(),
             private_key: self.key.clone(),
diff --git a/proxmox-acme-api/src/certificate_helpers.rs b/proxmox-acme-api/src/certificate_helpers.rs
index 323f4b4a..d43e8f62 100644
--- a/proxmox-acme-api/src/certificate_helpers.rs
+++ b/proxmox-acme-api/src/certificate_helpers.rs
@@ -10,6 +10,7 @@ use openssl::rsa::Rsa;
 use openssl::x509::{X509, X509Builder};
 
 use proxmox_acme::async_client::AcmeClient;
+use proxmox_http::ProxyConfig;
 use proxmox_log::{info, warn};
 use proxmox_rest_server::WorkerTask;
 
@@ -18,10 +19,14 @@ use crate::types::{AcmeConfig, AcmeDomain};
 
 const ACME_POLL_TIMEOUT: Duration = Duration::from_secs(5 * 60);
 
-pub async fn revoke_certificate(acme_config: &AcmeConfig, certificate: &[u8]) -> Result<(), Error> {
+pub async fn revoke_certificate(
+    acme_config: &AcmeConfig,
+    certificate: &[u8],
+    proxy_config: Option<ProxyConfig>,
+) -> Result<(), Error> {
     let mut acme = super::account_config::load_account_config(&acme_config.account)
         .await?
-        .client();
+        .client(proxy_config);
 
     acme.revoke_certificate(certificate, None).await?;
 
@@ -37,6 +42,7 @@ pub async fn order_certificate(
     worker: Arc<WorkerTask>,
     acme_config: &AcmeConfig,
     domains: &[AcmeDomain],
+    proxy_config: Option<ProxyConfig>,
 ) -> Result<Option<OrderedCertificate>, Error> {
     use proxmox_acme::authorization::Status;
     use proxmox_acme::order::Identifier;
@@ -55,7 +61,7 @@ pub async fn order_certificate(
 
     let mut acme = super::account_config::load_account_config(&acme_config.account)
         .await?
-        .client();
+        .client(proxy_config);
 
     let (plugins, _) = super::plugin_config::plugin_config()?;
 
-- 
2.47.3





  parent reply	other threads:[~2026-10-08 15:33 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08 15:33 [PATCH proxmox{,-backup,-datacenter-manager} 0/4] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 1/2] acme: async_client: support HTTP proxies Samuel Rufinatscha
2026-10-08 15:33 ` Samuel Rufinatscha [this message]
2026-10-08 15:33 ` [PATCH proxmox-backup 1/1] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox-datacenter-manager " Samuel Rufinatscha

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261008153323.293158-3-s.rufinatscha@proxmox.com \
    --to=s.rufinatscha@proxmox.com \
    --cc=pbs-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal