From: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
To: pbs-devel@lists.proxmox.com
Subject: [PATCH proxmox-backup 1/1] fix #6173: acme: use the configured HTTP proxy
Date: Thu, 8 Oct 2026 17:33:21 +0200 [thread overview]
Message-ID: <20261008153323.293158-4-s.rufinatscha@proxmox.com> (raw)
In-Reply-To: <20261008153323.293158-1-s.rufinatscha@proxmox.com>
ACME requests ignore the node's HTTP proxy setting and fail when the
CA is reachable only through a proxy.
Pass the node proxy configuration to each ACME operation that contacts
the CA.
Link: https://bugzilla.proxmox.com/show_bug.cgi?id=6173
Signed-off-by: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
---
src/api2/config/acme.rs | 10 +++++++---
src/api2/node/certificates.rs | 8 ++++++--
src/bin/proxmox_backup_manager/acme.rs | 4 +++-
3 files changed, 16 insertions(+), 6 deletions(-)
diff --git a/src/api2/config/acme.rs b/src/api2/config/acme.rs
index 16f24ea55..20f73e70a 100644
--- a/src/api2/config/acme.rs
+++ b/src/api2/config/acme.rs
@@ -170,6 +170,7 @@ fn register_account(
tos_url,
Some(directory),
eab_kid.zip(eab_hmac_key),
+ pbs_config::node::node_http_proxy_config()?,
)
.await?;
@@ -210,7 +211,8 @@ pub fn update_account(
auth_id.to_string(),
true,
move |_worker| async move {
- proxmox_acme_api::update_account(&name, contact).await?;
+ let proxy_config = pbs_config::node::node_http_proxy_config()?;
+ proxmox_acme_api::update_account(&name, contact, proxy_config).await?;
Ok(())
},
@@ -248,7 +250,8 @@ pub fn deactivate_account(
auth_id.to_string(),
true,
move |_worker| async move {
- proxmox_acme_api::deactivate_account(&name, force).await?;
+ let proxy_config = pbs_config::node::node_http_proxy_config()?;
+ proxmox_acme_api::deactivate_account(&name, force, proxy_config).await?;
Ok(())
},
@@ -276,7 +279,8 @@ pub fn deactivate_account(
)]
/// Get the Terms of Service URL for an ACME directory.
async fn get_tos(directory: Option<String>) -> Result<Option<String>, Error> {
- proxmox_acme_api::get_tos(directory).await
+ let proxy_config = pbs_config::node::node_http_proxy_config()?;
+ proxmox_acme_api::get_tos(directory, proxy_config).await
}
#[api(
diff --git a/src/api2/node/certificates.rs b/src/api2/node/certificates.rs
index 3df05b020..e93e84f93 100644
--- a/src/api2/node/certificates.rs
+++ b/src/api2/node/certificates.rs
@@ -368,6 +368,7 @@ fn spawn_certificate_worker(
let auth_id = rpcenv.get_auth_id().unwrap();
let acme_config = node_config.acme_config()?;
+ let proxy_config = node_config.http_proxy();
let domains = node_config.acme_domains().try_fold(
Vec::<AcmeDomain>::new(),
@@ -385,7 +386,8 @@ fn spawn_certificate_worker(
WorkerTask::spawn(name, None, auth_id, true, move |worker| async move {
let work = || async {
if let Some(cert) =
- proxmox_acme_api::order_certificate(worker, &acme_config, &domains).await?
+ proxmox_acme_api::order_certificate(worker, &acme_config, &domains, proxy_config)
+ .await?
{
crate::config::set_proxy_certificate(&cert.certificate, &cert.private_key_pem)?;
crate::server::reload_proxy_certificate().await?;
@@ -423,6 +425,7 @@ pub fn revoke_acme_cert(rpcenv: &mut dyn RpcEnvironment) -> Result<String, Error
let auth_id = rpcenv.get_auth_id().unwrap();
let acme_config = node_config.acme_config()?;
+ let proxy_config = node_config.http_proxy();
WorkerTask::spawn(
"acme-revoke-cert",
@@ -431,7 +434,8 @@ pub fn revoke_acme_cert(rpcenv: &mut dyn RpcEnvironment) -> Result<String, Error
true,
move |_worker| async move {
info!("Revoking old certificate");
- proxmox_acme_api::revoke_certificate(&acme_config, cert_pem.as_bytes()).await?;
+ proxmox_acme_api::revoke_certificate(&acme_config, cert_pem.as_bytes(), proxy_config)
+ .await?;
info!("Deleting certificate and regenerating a self-signed one");
delete_custom_certificate().await?;
Ok(())
diff --git a/src/bin/proxmox_backup_manager/acme.rs b/src/bin/proxmox_backup_manager/acme.rs
index ed9e5868c..9ef4479b9 100644
--- a/src/bin/proxmox_backup_manager/acme.rs
+++ b/src/bin/proxmox_backup_manager/acme.rs
@@ -141,7 +141,8 @@ async fn register_account(
};
println!("Attempting to fetch Terms of Service from {directory_url:?}");
- let mut client = AcmeClient::new(directory_url.clone());
+ let proxy_config = pbs_config::node::node_http_proxy_config()?;
+ let mut client = AcmeClient::with_proxy(directory_url.clone(), proxy_config.clone());
let directory = client.directory().await?;
let tos_agreed = if let Some(tos_url) = directory.terms_of_service_url() {
println!("Terms of Service: {tos_url}");
@@ -196,6 +197,7 @@ async fn register_account(
tos_agreed,
Some(directory_url),
eab_creds,
+ proxy_config,
)
.await?;
--
2.47.3
next prev parent reply other threads:[~2026-10-08 15:33 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 15:33 [PATCH proxmox{,-backup,-datacenter-manager} 0/4] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 1/2] acme: async_client: support HTTP proxies Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 2/2] acme-api: " Samuel Rufinatscha
2026-10-08 15:33 ` Samuel Rufinatscha [this message]
2026-10-08 15:33 ` [PATCH proxmox-datacenter-manager 1/1] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008153323.293158-4-s.rufinatscha@proxmox.com \
--to=s.rufinatscha@proxmox.com \
--cc=pbs-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.