From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 0C3A91FF0E5 for ; Wed, 29 Jul 2026 11:01:59 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 7504420A6B; Wed, 29 Jul 2026 11:01:58 +0200 (CEST) Message-ID: Date: Wed, 29 Jul 2026 11:01:43 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH proxmox{,-backup,-datacenter-manager} 0/7] acme: fix #6372 implement basic ARI support To: Shan Shaji , pbs-devel@lists.proxmox.com, pdm-devel@lists.proxmox.com References: <20260625141337.181684-1-m.federanko@proxmox.com> Content-Language: en-US From: Manuel Federanko In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1785315665497 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.350 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_LOW -0.7 Sender listed at https://www.dnswl.org/, low trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: 22UITSAM37IO5B7AFI5WZRDBIXR24HEG X-Message-ID-Hash: 22UITSAM37IO5B7AFI5WZRDBIXR24HEG X-MailFrom: m.federanko@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Backup Server development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Thanks for testing. On 2026-07-27 6:15 PM, Shan Shaji wrote: > Hi, > > I applied the patches and performed some testing with Proxmox Backup Server. > > * In the UI, the force option is always set to true, so the lead-time check is > skipped and a new certificate is ordered every time. > * I ordered a certificate through the UI, which generated a certificate valid from: > > 2026-07-27 16:40:42 to 2026-10-25 15:40:41 > > * Then, tried to order the certificate using proxmox-backup-manager with > the --force option set to false. The certificate was not renewed, and > the renewal time from the suggested window was shown in the task log. > However, it was not displayed in the console, as I mentioned in an > earlier reply. > Since the ARI workflow is a bit more involved I moved these checks into the worker process. I'm not sure how best to go about passing messages back at the CLI, but would also prefer this. Suggestions are welcome :) > Certificate is scheduled for renewal in 1M 4w 2d 8h 33m 13s by ARI > > * Now deleted the custom certificate. Since PBS was now using the self-signed > certificate, the initial ordering request failed because it included a > certificate ID that the server could not parse. It then retried without the > ARI certificate ID, and the request succeeded. Observed the same behavior > when ordering through the CLI using proxmox-backup-manager, as long as > the --force option was set to true. > > However, when --force is set to false, parsing the ARI certificate ID fails > and the certificate is not created. > > TASK ERROR: urn:ietf:params:acme:error:malformed: Parsing ARI CertID failed: urn:ietf:params:acme:error:malformed :: Invalid path > > Shouldn't we also need to retry without the certificate ID in this case? > I may have missed something, so please correct me if I am wrong. IMO we could either improve the error here or retry when ari parsing fails, I'll look into it. > Will do further testing tomorrow. > > On Thu Jun 25, 2026 at 4:13 PM CEST, Manuel Federanko wrote: >> >> This series implements basic ACME ARI [0] support for Proxmox Backup >> Server and Proxmox Datacenter Manager. Currently both projects renew >> once a fixed time has passed: >> > [snip]