From: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
To: pbs-devel@lists.proxmox.com
Subject: [PATCH proxmox-datacenter-manager 1/1] fix #6173: acme: use the configured HTTP proxy
Date: Thu, 8 Oct 2026 17:33:22 +0200 [thread overview]
Message-ID: <20261008153323.293158-5-s.rufinatscha@proxmox.com> (raw)
In-Reply-To: <20261008153323.293158-1-s.rufinatscha@proxmox.com>
ACME requests ignore the node's HTTP proxy setting and fail when the
CA is reachable only through a proxy.
Pass the node proxy configuration to each ACME operation that contacts
the CA.
Link: https://bugzilla.proxmox.com/show_bug.cgi?id=6173
Signed-off-by: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
---
cli/admin/src/acme.rs | 4 +++-
server/src/api/config/acme.rs | 26 ++++++++++++++++++++------
server/src/api/nodes/certificates.rs | 9 +++++++--
3 files changed, 30 insertions(+), 9 deletions(-)
diff --git a/cli/admin/src/acme.rs b/cli/admin/src/acme.rs
index e61bb1ef..28a29769 100644
--- a/cli/admin/src/acme.rs
+++ b/cli/admin/src/acme.rs
@@ -146,7 +146,9 @@ async fn register_account(
};
println!("Attempting to fetch Terms of Service from {directory_url:?}");
- let mut client = AcmeClient::new(directory_url.clone());
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ let mut client = AcmeClient::with_proxy(directory_url.clone(), proxy_config);
let directory = client.directory().await?;
let tos_agreed = if let Some(tos_url) = directory.terms_of_service_url() {
println!("Terms of Service: {tos_url}");
diff --git a/server/src/api/config/acme.rs b/server/src/api/config/acme.rs
index 838ad173..f852fa45 100644
--- a/server/src/api/config/acme.rs
+++ b/server/src/api/config/acme.rs
@@ -136,9 +136,17 @@ pub fn register_account(
move |_worker| async move {
proxmox_log::info!("Registering ACME account '{}'...", &name,);
- let location =
- proxmox_acme_api::register_account(&name, contact, tos_url, directory, eab_cread)
- .await?;
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ let location = proxmox_acme_api::register_account(
+ &name,
+ contact,
+ tos_url,
+ directory,
+ eab_cread,
+ proxy_config,
+ )
+ .await?;
proxmox_log::info!("Registration successful, account URL: {}", location);
@@ -198,7 +206,9 @@ pub fn update_account(
move |_worker| async move {
proxmox_log::info!("Update ACME account '{}'...", &name,);
- proxmox_acme_api::update_account(&name, contact).await?;
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ proxmox_acme_api::update_account(&name, contact, proxy_config).await?;
proxmox_log::info!("Update ACME account '{}' successful", &name,);
@@ -243,7 +253,9 @@ pub fn deactivate_account(
move |_worker| async move {
proxmox_log::info!("Deactivate ACME account '{}'...", &name,);
- proxmox_acme_api::deactivate_account(&name, force).await?;
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ proxmox_acme_api::deactivate_account(&name, force, proxy_config).await?;
proxmox_log::info!("Deactivate ACME account '{}' successful", &name,);
@@ -433,5 +445,7 @@ fn get_directories() -> Result<&'static [KnownAcmeDirectory], Error> {
)]
/// Get the Terms of Service URL for an ACME directory.
async fn get_tos(directory: Option<String>) -> Result<Option<String>, Error> {
- proxmox_acme_api::get_tos(directory).await
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ proxmox_acme_api::get_tos(directory, proxy_config).await
}
diff --git a/server/src/api/nodes/certificates.rs b/server/src/api/nodes/certificates.rs
index c3765415..753a8c0a 100644
--- a/server/src/api/nodes/certificates.rs
+++ b/server/src/api/nodes/certificates.rs
@@ -281,8 +281,11 @@ fn spawn_certificate_worker(
WorkerTask::spawn(name, None, auth_id, true, move |worker| async move {
let work = || async {
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
if let Some(cert) =
- proxmox_acme_api::order_certificate(worker, &acme_config, &domains).await?
+ proxmox_acme_api::order_certificate(worker, &acme_config, &domains, proxy_config)
+ .await?
{
crate::auth::certs::set_api_certificate(&cert.certificate, &cert.private_key_pem)?;
crate::reload_api_certificate().await?;
@@ -336,7 +339,9 @@ pub fn revoke_acme_cert(rpcenv: &mut dyn RpcEnvironment) -> Result<String, Error
true,
move |_worker| async move {
info!("Revoking old certificate");
- proxmox_acme_api::revoke_certificate(&acme_config, &cert_pem).await?;
+ let (node_config, _) = pdm_config::node::config()?;
+ let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+ proxmox_acme_api::revoke_certificate(&acme_config, &cert_pem, proxy_config).await?;
info!("Deleting certificate and regenerating a self-signed one");
delete_custom_certificate().await?;
Ok(())
--
2.47.3
prev parent reply other threads:[~2026-10-08 15:33 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 15:33 [PATCH proxmox{,-backup,-datacenter-manager} 0/4] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 1/2] acme: async_client: support HTTP proxies Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 2/2] acme-api: " Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox-backup 1/1] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` Samuel Rufinatscha [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008153323.293158-5-s.rufinatscha@proxmox.com \
--to=s.rufinatscha@proxmox.com \
--cc=pbs-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox