From: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
To: pbs-devel@lists.proxmox.com
Subject: [PATCH proxmox-datacenter-manager 1/1] fix #6173: acme: use the configured HTTP proxy
Date: Thu, 8 Oct 2026 17:33:22 +0200 [thread overview]
Message-ID: <20261008153323.293158-5-s.rufinatscha@proxmox.com> (raw)
In-Reply-To: <20261008153323.293158-1-s.rufinatscha@proxmox.com>
ACME requests ignore the node's HTTP proxy setting and fail when the
CA is reachable only through a proxy.
Pass the node proxy configuration to each ACME operation that contacts
the CA.
Link: https://bugzilla.proxmox.com/show_bug.cgi?id=6173
Signed-off-by: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
---
cli/admin/src/acme.rs | 4 +++-
server/src/api/config/acme.rs | 26 ++++++++++++++++++++------
server/src/api/nodes/certificates.rs | 9 +++++++--
3 files changed, 30 insertions(+), 9 deletions(-)
diff --git a/cli/admin/src/acme.rs b/cli/admin/src/acme.rs
index e61bb1ef..28a29769 100644
--- a/cli/admin/src/acme.rs
+++ b/cli/admin/src/acme.rs
@@ -146,7 +146,9 @@ async fn register_account(
};
println!("Attempting to fetch Terms of Service from {directory_url:?}");
- let mut client = AcmeClient::new(directory_url.clone());
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ let mut client = AcmeClient::with_proxy(directory_url.clone(), proxy_config);
let directory = client.directory().await?;
let tos_agreed = if let Some(tos_url) = directory.terms_of_service_url() {
println!("Terms of Service: {tos_url}");
diff --git a/server/src/api/config/acme.rs b/server/src/api/config/acme.rs
index 838ad173..f852fa45 100644
--- a/server/src/api/config/acme.rs
+++ b/server/src/api/config/acme.rs
@@ -136,9 +136,17 @@ pub fn register_account(
move |_worker| async move {
proxmox_log::info!("Registering ACME account '{}'...", &name,);
- let location =
- proxmox_acme_api::register_account(&name, contact, tos_url, directory, eab_cread)
- .await?;
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ let location = proxmox_acme_api::register_account(
+ &name,
+ contact,
+ tos_url,
+ directory,
+ eab_cread,
+ proxy_config,
+ )
+ .await?;
proxmox_log::info!("Registration successful, account URL: {}", location);
@@ -198,7 +206,9 @@ pub fn update_account(
move |_worker| async move {
proxmox_log::info!("Update ACME account '{}'...", &name,);
- proxmox_acme_api::update_account(&name, contact).await?;
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ proxmox_acme_api::update_account(&name, contact, proxy_config).await?;
proxmox_log::info!("Update ACME account '{}' successful", &name,);
@@ -243,7 +253,9 @@ pub fn deactivate_account(
move |_worker| async move {
proxmox_log::info!("Deactivate ACME account '{}'...", &name,);
- proxmox_acme_api::deactivate_account(&name, force).await?;
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ proxmox_acme_api::deactivate_account(&name, force, proxy_config).await?;
proxmox_log::info!("Deactivate ACME account '{}' successful", &name,);
@@ -433,5 +445,7 @@ fn get_directories() -> Result<&'static [KnownAcmeDirectory], Error> {
)]
/// Get the Terms of Service URL for an ACME directory.
async fn get_tos(directory: Option<String>) -> Result<Option<String>, Error> {
- proxmox_acme_api::get_tos(directory).await
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ proxmox_acme_api::get_tos(directory, proxy_config).await
}
diff --git a/server/src/api/nodes/certificates.rs b/server/src/api/nodes/certificates.rs
index c3765415..753a8c0a 100644
--- a/server/src/api/nodes/certificates.rs
+++ b/server/src/api/nodes/certificates.rs
@@ -281,8 +281,11 @@ fn spawn_certificate_worker(
WorkerTask::spawn(name, None, auth_id, true, move |worker| async move {
let work = || async {
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
if let Some(cert) =
- proxmox_acme_api::order_certificate(worker, &acme_config, &domains).await?
+ proxmox_acme_api::order_certificate(worker, &acme_config, &domains, proxy_config)
+ .await?
{
crate::auth::certs::set_api_certificate(&cert.certificate, &cert.private_key_pem)?;
crate::reload_api_certificate().await?;
@@ -336,7 +339,9 @@ pub fn revoke_acme_cert(rpcenv: &mut dyn RpcEnvironment) -> Result<String, Error
true,
move |_worker| async move {
info!("Revoking old certificate");
- proxmox_acme_api::revoke_certificate(&acme_config, &cert_pem).await?;
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ proxmox_acme_api::revoke_certificate(&acme_config, &cert_pem, proxy_config).await?;
info!("Deleting certificate and regenerating a self-signed one");
delete_custom_certificate().await?;
Ok(())
--
2.47.3
prev parent reply other threads:[~2026-10-08 15:33 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 15:33 [PATCH proxmox{,-backup,-datacenter-manager} 0/4] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 1/2] acme: async_client: support HTTP proxies Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 2/2] acme-api: " Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox-backup 1/1] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` Samuel Rufinatscha [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008153323.293158-5-s.rufinatscha@proxmox.com \
--to=s.rufinatscha@proxmox.com \
--cc=pbs-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.