From: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
To: pbs-devel@lists.proxmox.com
Subject: [PATCH proxmox-backup 1/1] fix #6173: acme: use the configured HTTP proxy
Date: Thu, 8 Oct 2026 17:33:21 +0200 [thread overview]
Message-ID: <20261008153323.293158-4-s.rufinatscha@proxmox.com> (raw)
In-Reply-To: <20261008153323.293158-1-s.rufinatscha@proxmox.com>
ACME requests ignore the node's HTTP proxy setting and fail when the
CA is reachable only through a proxy.
Pass the node proxy configuration to each ACME operation that contacts
the CA.
Link: https://bugzilla.proxmox.com/show_bug.cgi?id=6173
Signed-off-by: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
---
src/api2/config/acme.rs | 10 +++++++---
src/api2/node/certificates.rs | 8 ++++++--
src/bin/proxmox_backup_manager/acme.rs | 4 +++-
3 files changed, 16 insertions(+), 6 deletions(-)
diff --git a/src/api2/config/acme.rs b/src/api2/config/acme.rs
index 16f24ea55..20f73e70a 100644
--- a/src/api2/config/acme.rs
+++ b/src/api2/config/acme.rs
@@ -170,6 +170,7 @@ fn register_account(
tos_url,
Some(directory),
eab_kid.zip(eab_hmac_key),
+ pbs_config::node::node_http_proxy_config()?,
)
.await?;
@@ -210,7 +211,8 @@ pub fn update_account(
auth_id.to_string(),
true,
move |_worker| async move {
- proxmox_acme_api::update_account(&name, contact).await?;
+ let proxy_config = pbs_config::node::node_http_proxy_config()?;
+ proxmox_acme_api::update_account(&name, contact, proxy_config).await?;
Ok(())
},
@@ -248,7 +250,8 @@ pub fn deactivate_account(
auth_id.to_string(),
true,
move |_worker| async move {
- proxmox_acme_api::deactivate_account(&name, force).await?;
+ let proxy_config = pbs_config::node::node_http_proxy_config()?;
+ proxmox_acme_api::deactivate_account(&name, force, proxy_config).await?;
Ok(())
},
@@ -276,7 +279,8 @@ pub fn deactivate_account(
)]
/// Get the Terms of Service URL for an ACME directory.
async fn get_tos(directory: Option<String>) -> Result<Option<String>, Error> {
- proxmox_acme_api::get_tos(directory).await
+ let proxy_config = pbs_config::node::node_http_proxy_config()?;
+ proxmox_acme_api::get_tos(directory, proxy_config).await
}
#[api(
diff --git a/src/api2/node/certificates.rs b/src/api2/node/certificates.rs
index 3df05b020..e93e84f93 100644
--- a/src/api2/node/certificates.rs
+++ b/src/api2/node/certificates.rs
@@ -368,6 +368,7 @@ fn spawn_certificate_worker(
let auth_id = rpcenv.get_auth_id().unwrap();
let acme_config = node_config.acme_config()?;
+ let proxy_config = node_config.http_proxy();
let domains = node_config.acme_domains().try_fold(
Vec::<AcmeDomain>::new(),
@@ -385,7 +386,8 @@ fn spawn_certificate_worker(
WorkerTask::spawn(name, None, auth_id, true, move |worker| async move {
let work = || async {
if let Some(cert) =
- proxmox_acme_api::order_certificate(worker, &acme_config, &domains).await?
+ proxmox_acme_api::order_certificate(worker, &acme_config, &domains, proxy_config)
+ .await?
{
crate::config::set_proxy_certificate(&cert.certificate, &cert.private_key_pem)?;
crate::server::reload_proxy_certificate().await?;
@@ -423,6 +425,7 @@ pub fn revoke_acme_cert(rpcenv: &mut dyn RpcEnvironment) -> Result<String, Error
let auth_id = rpcenv.get_auth_id().unwrap();
let acme_config = node_config.acme_config()?;
+ let proxy_config = node_config.http_proxy();
WorkerTask::spawn(
"acme-revoke-cert",
@@ -431,7 +434,8 @@ pub fn revoke_acme_cert(rpcenv: &mut dyn RpcEnvironment) -> Result<String, Error
true,
move |_worker| async move {
info!("Revoking old certificate");
- proxmox_acme_api::revoke_certificate(&acme_config, cert_pem.as_bytes()).await?;
+ proxmox_acme_api::revoke_certificate(&acme_config, cert_pem.as_bytes(), proxy_config)
+ .await?;
info!("Deleting certificate and regenerating a self-signed one");
delete_custom_certificate().await?;
Ok(())
diff --git a/src/bin/proxmox_backup_manager/acme.rs b/src/bin/proxmox_backup_manager/acme.rs
index ed9e5868c..9ef4479b9 100644
--- a/src/bin/proxmox_backup_manager/acme.rs
+++ b/src/bin/proxmox_backup_manager/acme.rs
@@ -141,7 +141,8 @@ async fn register_account(
};
println!("Attempting to fetch Terms of Service from {directory_url:?}");
- let mut client = AcmeClient::new(directory_url.clone());
+ let proxy_config = pbs_config::node::node_http_proxy_config()?;
+ let mut client = AcmeClient::with_proxy(directory_url.clone(), proxy_config.clone());
let directory = client.directory().await?;
let tos_agreed = if let Some(tos_url) = directory.terms_of_service_url() {
println!("Terms of Service: {tos_url}");
@@ -196,6 +197,7 @@ async fn register_account(
tos_agreed,
Some(directory_url),
eab_creds,
+ proxy_config,
)
.await?;
--
2.47.3
next prev parent reply other threads:[~2026-10-08 15:33 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 15:33 [PATCH proxmox{,-backup,-datacenter-manager} 0/4] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 1/2] acme: async_client: support HTTP proxies Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 2/2] acme-api: " Samuel Rufinatscha
2026-10-08 15:33 ` Samuel Rufinatscha [this message]
2026-10-08 15:33 ` [PATCH proxmox-datacenter-manager 1/1] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008153323.293158-4-s.rufinatscha@proxmox.com \
--to=s.rufinatscha@proxmox.com \
--cc=pbs-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox