From: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
To: pbs-devel@lists.proxmox.com
Subject: [PATCH proxmox 2/2] acme-api: support HTTP proxies
Date: Thu, 8 Oct 2026 17:33:20 +0200 [thread overview]
Message-ID: <20261008153323.293158-3-s.rufinatscha@proxmox.com> (raw)
In-Reply-To: <20261008153323.293158-1-s.rufinatscha@proxmox.com>
Accept an optional proxy configuration for operations that contact
the ACME server and pass it to each new client.
Signed-off-by: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
---
proxmox-acme-api/Cargo.toml | 2 ++
proxmox-acme-api/src/account_api_impl.rs | 27 +++++++++++++++------
proxmox-acme-api/src/account_config.rs | 5 ++--
proxmox-acme-api/src/certificate_helpers.rs | 12 ++++++---
4 files changed, 34 insertions(+), 12 deletions(-)
diff --git a/proxmox-acme-api/Cargo.toml b/proxmox-acme-api/Cargo.toml
index 4bb1720b..9229d4ea 100644
--- a/proxmox-acme-api/Cargo.toml
+++ b/proxmox-acme-api/Cargo.toml
@@ -30,6 +30,7 @@ openssl = { workspace = true, optional = true }
proxmox-acme = { workspace = true, features = ["api-types"] }
proxmox-base64 = { workspace = true, optional = true }
proxmox-config-digest = { workspace = true, optional = true }
+proxmox-http = { workspace = true, optional = true }
proxmox-log = { workspace = true, optional = true }
proxmox-product-config = { workspace = true, optional = true }
proxmox-rest-server = { workspace = true, optional = true }
@@ -57,6 +58,7 @@ impl = [
"dep:proxmox-base64",
"dep:proxmox-config-digest",
+ "dep:proxmox-http",
"dep:proxmox-log",
"dep:proxmox-product-config",
"dep:proxmox-rest-server",
diff --git a/proxmox-acme-api/src/account_api_impl.rs b/proxmox-acme-api/src/account_api_impl.rs
index ef195908..d42a475f 100644
--- a/proxmox-acme-api/src/account_api_impl.rs
+++ b/proxmox-acme-api/src/account_api_impl.rs
@@ -7,6 +7,7 @@ use serde_json::json;
use proxmox_acme::async_client::AcmeClient;
use proxmox_acme::types::AccountData as AcmeAccountData;
+use proxmox_http::ProxyConfig;
use proxmox_log::warn;
use crate::account_config::AccountData;
@@ -41,9 +42,12 @@ pub async fn get_account(account_name: AcmeAccountName) -> Result<AccountInfo, E
})
}
-pub async fn get_tos(directory: Option<String>) -> Result<Option<String>, Error> {
+pub async fn get_tos(
+ directory: Option<String>,
+ proxy_config: Option<ProxyConfig>,
+) -> Result<Option<String>, Error> {
let directory = directory.unwrap_or_else(|| DEFAULT_ACME_DIRECTORY_ENTRY.url.to_string());
- Ok(AcmeClient::new(directory)
+ Ok(AcmeClient::with_proxy(directory, proxy_config)
.terms_of_service_url()
.await?
.map(str::to_owned))
@@ -55,11 +59,12 @@ pub async fn register_account(
tos_url: Option<String>,
directory_url: Option<String>,
eab_creds: Option<(String, String)>,
+ proxy_config: Option<ProxyConfig>,
) -> Result<String, Error> {
let directory_url =
directory_url.unwrap_or_else(|| DEFAULT_ACME_DIRECTORY_ENTRY.url.to_string());
- let mut client = AcmeClient::new(directory_url.clone());
+ let mut client = AcmeClient::with_proxy(directory_url.clone(), proxy_config);
let contact = account_contact_from_string(&contact);
let account = client
@@ -73,9 +78,13 @@ pub async fn register_account(
Ok(account.location)
}
-pub async fn deactivate_account(name: &AcmeAccountName, force: bool) -> Result<(), Error> {
+pub async fn deactivate_account(
+ name: &AcmeAccountName,
+ force: bool,
+ proxy_config: Option<ProxyConfig>,
+) -> Result<(), Error> {
let mut account_data = super::account_config::load_account_config(name).await?;
- let mut client = account_data.client();
+ let mut client = account_data.client(proxy_config);
match client
.update_account(&json!({"status": "deactivated"}))
@@ -99,9 +108,13 @@ pub async fn deactivate_account(name: &AcmeAccountName, force: bool) -> Result<(
Ok(())
}
-pub async fn update_account(name: &AcmeAccountName, contact: Option<String>) -> Result<(), Error> {
+pub async fn update_account(
+ name: &AcmeAccountName,
+ contact: Option<String>,
+ proxy_config: Option<ProxyConfig>,
+) -> Result<(), Error> {
let mut account_data = super::account_config::load_account_config(name).await?;
- let mut client = account_data.client();
+ let mut client = account_data.client(proxy_config);
let data = match contact {
Some(contact) => json!({
diff --git a/proxmox-acme-api/src/account_config.rs b/proxmox-acme-api/src/account_config.rs
index ce128c45..387f002c 100644
--- a/proxmox-acme-api/src/account_config.rs
+++ b/proxmox-acme-api/src/account_config.rs
@@ -8,6 +8,7 @@ use std::path::{Path, PathBuf};
use anyhow::{Error, bail, format_err};
use serde::{Deserialize, Serialize};
+use proxmox_http::ProxyConfig;
use proxmox_product_config::replace_secret_config;
use proxmox_sys::error::SysError;
@@ -68,8 +69,8 @@ impl AccountData {
}
}
- pub fn client(&self) -> AcmeClient {
- let mut client = AcmeClient::new(self.directory_url.clone());
+ pub fn client(&self, proxy_config: Option<ProxyConfig>) -> AcmeClient {
+ let mut client = AcmeClient::with_proxy(self.directory_url.clone(), proxy_config);
client.set_account(Account {
location: self.location.clone(),
private_key: self.key.clone(),
diff --git a/proxmox-acme-api/src/certificate_helpers.rs b/proxmox-acme-api/src/certificate_helpers.rs
index 323f4b4a..d43e8f62 100644
--- a/proxmox-acme-api/src/certificate_helpers.rs
+++ b/proxmox-acme-api/src/certificate_helpers.rs
@@ -10,6 +10,7 @@ use openssl::rsa::Rsa;
use openssl::x509::{X509, X509Builder};
use proxmox_acme::async_client::AcmeClient;
+use proxmox_http::ProxyConfig;
use proxmox_log::{info, warn};
use proxmox_rest_server::WorkerTask;
@@ -18,10 +19,14 @@ use crate::types::{AcmeConfig, AcmeDomain};
const ACME_POLL_TIMEOUT: Duration = Duration::from_secs(5 * 60);
-pub async fn revoke_certificate(acme_config: &AcmeConfig, certificate: &[u8]) -> Result<(), Error> {
+pub async fn revoke_certificate(
+ acme_config: &AcmeConfig,
+ certificate: &[u8],
+ proxy_config: Option<ProxyConfig>,
+) -> Result<(), Error> {
let mut acme = super::account_config::load_account_config(&acme_config.account)
.await?
- .client();
+ .client(proxy_config);
acme.revoke_certificate(certificate, None).await?;
@@ -37,6 +42,7 @@ pub async fn order_certificate(
worker: Arc<WorkerTask>,
acme_config: &AcmeConfig,
domains: &[AcmeDomain],
+ proxy_config: Option<ProxyConfig>,
) -> Result<Option<OrderedCertificate>, Error> {
use proxmox_acme::authorization::Status;
use proxmox_acme::order::Identifier;
@@ -55,7 +61,7 @@ pub async fn order_certificate(
let mut acme = super::account_config::load_account_config(&acme_config.account)
.await?
- .client();
+ .client(proxy_config);
let (plugins, _) = super::plugin_config::plugin_config()?;
--
2.47.3
next prev parent reply other threads:[~2026-10-08 15:33 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 15:33 [PATCH proxmox{,-backup,-datacenter-manager} 0/4] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 1/2] acme: async_client: support HTTP proxies Samuel Rufinatscha
2026-10-08 15:33 ` Samuel Rufinatscha [this message]
2026-10-08 15:33 ` [PATCH proxmox-backup 1/1] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox-datacenter-manager " Samuel Rufinatscha
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008153323.293158-3-s.rufinatscha@proxmox.com \
--to=s.rufinatscha@proxmox.com \
--cc=pbs-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox