From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 5E22C1FF0AF for ; Thu, 08 Oct 2026 17:33:45 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 2E42721586; Thu, 08 Oct 2026 17:33:44 +0200 (CEST) From: Samuel Rufinatscha To: pbs-devel@lists.proxmox.com Subject: [PATCH proxmox{,-backup,-datacenter-manager} 0/4] fix #6173: acme: use the configured HTTP proxy Date: Thu, 8 Oct 2026 17:33:18 +0200 Message-ID: <20261008153323.293158-1-s.rufinatscha@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791473608055 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.267 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: NWS5F3DBHIKVWUTJKQTGISZ4HWPVAAGK X-Message-ID-Hash: NWS5F3DBHIKVWUTJKQTGISZ4HWPVAAGK X-MailFrom: s.rufinatscha@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Backup Server development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: ACME requests in PBS and PDM ignore the node's HTTP proxy setting and fail when the CA is reachable only through a proxy [0]. Add optional proxy support to the shared ACME client and pass the node proxy configuration to each operation that contacts the CA. Testing: Reproduced the issue on PBS 4.2 using Pebble [1] as the ACME server and Tinyproxy [2] as the HTTP proxy configured in PBS. Added a firewall rule to block direct access to Pebble while allowing connections through Tinyproxy. Operations succeeded through the configured proxy. Tested for: (1) HTTP-01 and DNS-01, including proxies requiring authentication. (2) Automatic renewal using a short-lived Pebble certificate. (3) Changed the HTTP proxy setting to a second Tinyproxy instance without restarting the PBS services. The next ACME operations used the new proxy. (4) PDM was built against the shared libraries (only). Maintainer notes: - proxmox-acme-api has breaking changes because of the extra Option argument. - proxmox-acme-api adds the proxmox-http dependency to the impl feature [0] https://bugzilla.proxmox.com/show_bug.cgi?id=6173 [1] https://github.com/letsencrypt/pebble [2] https://tinyproxy.github.io/ proxmox: Samuel Rufinatscha (2): acme: async_client: support HTTP proxies acme-api: support HTTP proxies proxmox-acme-api/Cargo.toml | 2 ++ proxmox-acme-api/src/account_api_impl.rs | 27 +++++++++++++++------ proxmox-acme-api/src/account_config.rs | 5 ++-- proxmox-acme-api/src/certificate_helpers.rs | 12 ++++++--- proxmox-acme/src/async_client.rs | 9 +++++-- 5 files changed, 41 insertions(+), 14 deletions(-) proxmox-backup: Samuel Rufinatscha (1): fix #6173: acme: use the configured HTTP proxy src/api2/config/acme.rs | 10 +++++++--- src/api2/node/certificates.rs | 8 ++++++-- src/bin/proxmox_backup_manager/acme.rs | 4 +++- 3 files changed, 16 insertions(+), 6 deletions(-) proxmox-datacenter-manager: Samuel Rufinatscha (1): fix #6173: acme: use the configured HTTP proxy cli/admin/src/acme.rs | 4 +++- server/src/api/config/acme.rs | 26 ++++++++++++++++++++------ server/src/api/nodes/certificates.rs | 9 +++++++-- 3 files changed, 30 insertions(+), 9 deletions(-) Summary over all repositories: 11 files changed, 87 insertions(+), 29 deletions(-) -- Generated by git-murpp 0.8.1