public inbox for pbs-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
To: pbs-devel@lists.proxmox.com
Subject: [PATCH proxmox-datacenter-manager 1/1] fix #6173: acme: use the configured HTTP proxy
Date: Thu,  8 Oct 2026 17:33:22 +0200	[thread overview]
Message-ID: <20261008153323.293158-5-s.rufinatscha@proxmox.com> (raw)
In-Reply-To: <20261008153323.293158-1-s.rufinatscha@proxmox.com>

ACME requests ignore the node's HTTP proxy setting and fail when the
CA is reachable only through a proxy.

Pass the node proxy configuration to each ACME operation that contacts
the CA.

Link: https://bugzilla.proxmox.com/show_bug.cgi?id=6173
Signed-off-by: Samuel Rufinatscha <s.rufinatscha@proxmox.com>
---
 cli/admin/src/acme.rs                |  4 +++-
 server/src/api/config/acme.rs        | 26 ++++++++++++++++++++------
 server/src/api/nodes/certificates.rs |  9 +++++++--
 3 files changed, 30 insertions(+), 9 deletions(-)

diff --git a/cli/admin/src/acme.rs b/cli/admin/src/acme.rs
index e61bb1ef..28a29769 100644
--- a/cli/admin/src/acme.rs
+++ b/cli/admin/src/acme.rs
@@ -146,7 +146,9 @@ async fn register_account(
     };
 
     println!("Attempting to fetch Terms of Service from {directory_url:?}");
-    let mut client = AcmeClient::new(directory_url.clone());
+    let (node_config, _) = pdm_config::node::config()?;
+    let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+    let mut client = AcmeClient::with_proxy(directory_url.clone(), proxy_config);
     let directory = client.directory().await?;
     let tos_agreed = if let Some(tos_url) = directory.terms_of_service_url() {
         println!("Terms of Service: {tos_url}");
diff --git a/server/src/api/config/acme.rs b/server/src/api/config/acme.rs
index 838ad173..f852fa45 100644
--- a/server/src/api/config/acme.rs
+++ b/server/src/api/config/acme.rs
@@ -136,9 +136,17 @@ pub fn register_account(
         move |_worker| async move {
             proxmox_log::info!("Registering ACME account '{}'...", &name,);
 
-            let location =
-                proxmox_acme_api::register_account(&name, contact, tos_url, directory, eab_cread)
-                    .await?;
+            let (node_config, _) = pdm_config::node::config()?;
+            let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+            let location = proxmox_acme_api::register_account(
+                &name,
+                contact,
+                tos_url,
+                directory,
+                eab_cread,
+                proxy_config,
+            )
+            .await?;
 
             proxmox_log::info!("Registration successful, account URL: {}", location);
 
@@ -198,7 +206,9 @@ pub fn update_account(
         move |_worker| async move {
             proxmox_log::info!("Update ACME account '{}'...", &name,);
 
-            proxmox_acme_api::update_account(&name, contact).await?;
+            let (node_config, _) = pdm_config::node::config()?;
+            let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+            proxmox_acme_api::update_account(&name, contact, proxy_config).await?;
 
             proxmox_log::info!("Update ACME account '{}' successful", &name,);
 
@@ -243,7 +253,9 @@ pub fn deactivate_account(
         move |_worker| async move {
             proxmox_log::info!("Deactivate ACME account '{}'...", &name,);
 
-            proxmox_acme_api::deactivate_account(&name, force).await?;
+            let (node_config, _) = pdm_config::node::config()?;
+            let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+            proxmox_acme_api::deactivate_account(&name, force, proxy_config).await?;
 
             proxmox_log::info!("Deactivate ACME account '{}' successful", &name,);
 
@@ -433,5 +445,7 @@ fn get_directories() -> Result<&'static [KnownAcmeDirectory], Error> {
 )]
 /// Get the Terms of Service URL for an ACME directory.
 async fn get_tos(directory: Option<String>) -> Result<Option<String>, Error> {
-    proxmox_acme_api::get_tos(directory).await
+    let (node_config, _) = pdm_config::node::config()?;
+    let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+    proxmox_acme_api::get_tos(directory, proxy_config).await
 }
diff --git a/server/src/api/nodes/certificates.rs b/server/src/api/nodes/certificates.rs
index c3765415..753a8c0a 100644
--- a/server/src/api/nodes/certificates.rs
+++ b/server/src/api/nodes/certificates.rs
@@ -281,8 +281,11 @@ fn spawn_certificate_worker(
 
     WorkerTask::spawn(name, None, auth_id, true, move |worker| async move {
         let work = || async {
+            let (node_config, _) = pdm_config::node::config()?;
+            let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
             if let Some(cert) =
-                proxmox_acme_api::order_certificate(worker, &acme_config, &domains).await?
+                proxmox_acme_api::order_certificate(worker, &acme_config, &domains, proxy_config)
+                    .await?
             {
                 crate::auth::certs::set_api_certificate(&cert.certificate, &cert.private_key_pem)?;
                 crate::reload_api_certificate().await?;
@@ -336,7 +339,9 @@ pub fn revoke_acme_cert(rpcenv: &mut dyn RpcEnvironment) -> Result<String, Error
         true,
         move |_worker| async move {
             info!("Revoking old certificate");
-            proxmox_acme_api::revoke_certificate(&acme_config, &cert_pem).await?;
+            let (node_config, _) = pdm_config::node::config()?;
+            let proxy_config = pdm_config::node::get_http_proxy_config(&node_config);
+            proxmox_acme_api::revoke_certificate(&acme_config, &cert_pem, proxy_config).await?;
             info!("Deleting certificate and regenerating a self-signed one");
             delete_custom_certificate().await?;
             Ok(())
-- 
2.47.3





      parent reply	other threads:[~2026-10-08 15:33 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08 15:33 [PATCH proxmox{,-backup,-datacenter-manager} 0/4] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 1/2] acme: async_client: support HTTP proxies Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox 2/2] acme-api: " Samuel Rufinatscha
2026-10-08 15:33 ` [PATCH proxmox-backup 1/1] fix #6173: acme: use the configured HTTP proxy Samuel Rufinatscha
2026-10-08 15:33 ` Samuel Rufinatscha [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261008153323.293158-5-s.rufinatscha@proxmox.com \
    --to=s.rufinatscha@proxmox.com \
    --cc=pbs-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal