From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 9F60E1FF09B for ; Mon, 14 Sep 2026 18:19:48 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 5F81F215DD; Mon, 14 Sep 2026 18:19:48 +0200 (CEST) From: Samuel Rufinatscha To: pdm-devel@lists.proxmox.com Subject: [PATCH proxmox 3/3] fix #7166: acme-api: time out validation and finalization Date: Mon, 14 Sep 2026 18:19:31 +0200 Message-ID: <20260914161931.380138-4-s.rufinatscha@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260914161931.380138-1-s.rufinatscha@proxmox.com> References: <20260914161931.380138-1-s.rufinatscha@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1789402769104 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.500 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: HN2DM4UYRLBGGA3XMEN6X43UPSVT2SKO X-Message-ID-Hash: HN2DM4UYRLBGGA3XMEN6X43UPSVT2SKO X-MailFrom: s.rufinatscha@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Datacenter Manager development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Limit each domain's validation and order finalization to five minutes. Start the validation timeout after plugin setup so DNS propagation waits are unaffected, and clean up the plugin on timeout. Signed-off-by: Samuel Rufinatscha --- proxmox-acme-api/src/certificate_helpers.rs | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/proxmox-acme-api/src/certificate_helpers.rs b/proxmox-acme-api/src/certificate_helpers.rs index 771111fb..323f4b4a 100644 --- a/proxmox-acme-api/src/certificate_helpers.rs +++ b/proxmox-acme-api/src/certificate_helpers.rs @@ -16,6 +16,8 @@ use proxmox_rest_server::WorkerTask; use crate::CertificateInfo; use crate::types::{AcmeConfig, AcmeDomain}; +const ACME_POLL_TIMEOUT: Duration = Duration::from_secs(5 * 60); + pub async fn revoke_certificate(acme_config: &AcmeConfig, certificate: &[u8]) -> Result<(), Error> { let mut acme = super::account_config::load_account_config(&acme_config.account) .await? @@ -103,6 +105,9 @@ pub async fn order_certificate( let result = tokio::select! { biased; _ = worker.abort_future() => Err(format_err!("abort requested - aborting task")), + _ = tokio::time::sleep(ACME_POLL_TIMEOUT) => { + Err(format_err!("ACME validation for '{domain}' timed out")) + } result = request_validation(&mut acme, auth_url, validation_url) => result, }; @@ -126,6 +131,7 @@ pub async fn order_certificate( let certificate = tokio::select! { biased; _ = worker.abort_future() => bail!("abort requested - aborting task"), + _ = tokio::time::sleep(ACME_POLL_TIMEOUT) => bail!("ACME order finalization timed out"), result = finalize_order(&mut acme, &order.location, &csr.data) => result?, }; -- 2.47.3