all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: "Lukas Wagner" <l.wagner@proxmox.com>
To: "Christoph Heiss" <c.heiss@proxmox.com>, <pdm-devel@lists.proxmox.com>
Subject: Re: [PATCH installer 08/16] post-hook: generate and retrieve node certificate fingerprint
Date: Tue, 04 Aug 2026 13:39:16 +0200	[thread overview]
Message-ID: <DKG4PFT4PL8H.2ARIZQKM0L1VY@proxmox.com> (raw)
In-Reply-To: <20260731143910.936881-9-c.heiss@proxmox.com>

On Fri Jul 31, 2026 at 4:35 PM CEST, Christoph Heiss wrote:
>  
> +    /// First creates the initial node certificate, then computes the fingerprint from the freshly
> +    /// initialized proxy certificate.
> +    fn gather_node_cert_fingerprint(

I think since this function always generates the certificate, the name
gather_nod_cert_fingerprint is not ideal. Maybe call it
`generate_node_certificate`? A function with that name returning a
fingerprint of the generated cert seems plausible to me.

> +        target_path: &str,
> +        product: ProxmoxProduct,
> +        open_file: &dyn Fn(&str) -> Result<File>,
> +        run_cmd: &dyn Fn(&[&str]) -> Result<String>,
> +    ) -> Result<Option<String>> {
> +        println!("Generating node certificates ..");
> +
> +        match product {
> +            ProxmoxProduct::Pve => with_pmxcfs(target_path, |_| {
> +                run_cmd(&["pvecm", "updatecerts"])
> +                    .context("failed to generate node certificates")?;
> +                retrieve_cert_fingerprint(open_file("/etc/pve/local/pve-ssl.pem")?).map(Some)
> +            }),
> +            ProxmoxProduct::Pbs => {
> +                run_cmd(&["proxmox-backup-manager", "cert", "update"])
> +                    .context("failed to generate node certificates")?;
> +                retrieve_cert_fingerprint(open_file("/etc/proxmox-backup/proxy.pem")?).map(Some)
> +            }
> +            ProxmoxProduct::Pmg => {
> +                run_cmd(&["pmgconfig", "apicert"])
> +                    .context("failed to generate node certificates")?;
> +                retrieve_cert_fingerprint(open_file("/etc/pmg/pmg-api.pem")?).map(Some)
> +            }
> +            _ => Ok(None),
> +        }
> +    }
> +




  reply	other threads:[~2026-08-04 11:39 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-31 14:35 [PATCH proxmox/installer/datacenter-manager 00/16] auto-installer: add installed target systems as new remotes Christoph Heiss
2026-07-31 14:35 ` [PATCH proxmox 01/16] installer-types: drop unnecessary clippy attribute Christoph Heiss
2026-07-31 14:35 ` [PATCH proxmox 02/16] installer-types: post-hook: factor schema version into proper struct Christoph Heiss
2026-08-04 11:39   ` Lukas Wagner
2026-07-31 14:35 ` [PATCH proxmox 03/16] installer-types: post-hook: allow additional properties on api schema Christoph Heiss
2026-07-31 14:35 ` [PATCH proxmox 04/16] installer-types: post-hook: add api-token and cert-fingerprint options Christoph Heiss
2026-07-31 14:35 ` [PATCH proxmox 05/16] installer-types: systeminfo: add check for API token creation capability Christoph Heiss
2026-08-04 11:39   ` Lukas Wagner
2026-07-31 14:35 ` [PATCH installer 06/16] chroot: print full error if bind-mounting fails Christoph Heiss
2026-07-31 14:35 ` [PATCH installer 07/16] post-hook: re-use low-level config retrieval from proxmox-chroot Christoph Heiss
2026-07-31 14:35 ` [PATCH installer 08/16] post-hook: generate and retrieve node certificate fingerprint Christoph Heiss
2026-08-04 11:39   ` Lukas Wagner [this message]
2026-07-31 14:35 ` [PATCH installer 09/16] post-hook: support creating API token if requested in answer file Christoph Heiss
2026-08-04 11:39   ` Lukas Wagner
2026-07-31 14:35 ` [PATCH installer 10/16] auto: enforce https for post hook when generating an API token Christoph Heiss
2026-07-31 14:35 ` [PATCH installer 11/16] assistant: validate-answer: also verify post-hook settings if set Christoph Heiss
2026-07-31 14:35 ` [PATCH datacenter-manager 12/16] ui: auto-installer: spell out Proxmox Datacenter Manager Christoph Heiss
2026-07-31 14:35 ` [PATCH datacenter-manager 13/16] config: auto-install: add optional `post-hook-add-as-remote` field Christoph Heiss
2026-07-31 14:35 ` [PATCH datacenter-manager 14/16] api: auto-installer: add option for adding new remotes to PDM Christoph Heiss
2026-07-31 14:35 ` [PATCH datacenter-manager 15/16] ui: auto-installer: wizard: add checkbox to add target as new remote Christoph Heiss
2026-08-04 11:39   ` Lukas Wagner
2026-07-31 14:35 ` [PATCH datacenter-manager 16/16] docs: auto-installer: document adding targets as remotes afterwards Christoph Heiss
2026-07-31 22:05   ` Unsuscribe Pablo Méndez Segura
2026-08-04 11:39   ` [PATCH datacenter-manager 16/16] docs: auto-installer: document adding targets as remotes afterwards Lukas Wagner
2026-08-04 11:38 ` [PATCH proxmox/installer/datacenter-manager 00/16] auto-installer: add installed target systems as new remotes Lukas Wagner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DKG4PFT4PL8H.2ARIZQKM0L1VY@proxmox.com \
    --to=l.wagner@proxmox.com \
    --cc=c.heiss@proxmox.com \
    --cc=pdm-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal