From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id 6DD5895C56 for ; Wed, 28 Feb 2024 12:24:17 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 4B306A7AE for ; Wed, 28 Feb 2024 12:24:17 +0100 (CET) Received: from proxmox-new.maurer-it.com (proxmox-new.maurer-it.com [94.136.29.106]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by firstgate.proxmox.com (Proxmox) with ESMTPS for ; Wed, 28 Feb 2024 12:24:16 +0100 (CET) Received: from proxmox-new.maurer-it.com (localhost.localdomain [127.0.0.1]) by proxmox-new.maurer-it.com (Proxmox) with ESMTP id 6372447BC3 for ; Wed, 28 Feb 2024 12:24:16 +0100 (CET) From: Hannes Laimer To: pve-devel@lists.proxmox.com Date: Wed, 28 Feb 2024 12:24:11 +0100 Message-Id: <20240228112412.3982-2-h.laimer@proxmox.com> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20240228112412.3982-1-h.laimer@proxmox.com> References: <20240228112412.3982-1-h.laimer@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL -0.007 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record T_SCC_BODY_TEXT_LINE -0.01 - URIBL_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [dnschallenge.pm] Subject: [pve-devel] [PATCH proxmox-acme 1/1] dns-challenge: use configured datacenter http_proxy for acme dns challenges X-BeenThere: pve-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox VE development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 28 Feb 2024 11:24:17 -0000 the proxy is added to the plugin config so the `proxmox-acme` script exports it and it'll be used by curl when requests are made. Based on e1088f616ffc73a96ee3433f0ea07639ef7513e7 (reverted). Signed-off-by: Hannes Laimer --- src/PVE/ACME/DNSChallenge.pm | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/PVE/ACME/DNSChallenge.pm b/src/PVE/ACME/DNSChallenge.pm index 7214d88..29b741e 100644 --- a/src/PVE/ACME/DNSChallenge.pm +++ b/src/PVE/ACME/DNSChallenge.pm @@ -85,6 +85,9 @@ my $proxmox_acme_command = sub { my $dnsplugin = $data->{plugin}->{api}; my $plugin_conf_string = $data->{plugin}->{data}; + my $dccfg = PVE::Cluster::cfs_read_file('datacenter.cfg'); + my $proxy = $dccfg->{http_proxy}; + # for security reasons, we execute the command as nobody # we can't verify that the code of the DNSPlugins are harmless. my $cmd = ["setpriv", "--reuid", "nobody", "--regid", "nogroup", "--clear-groups", "--reset-env", "--"]; @@ -99,6 +102,7 @@ my $proxmox_acme_command = sub { } my $input = "$txtvalue\n"; $input .= "$plugin_conf_string\n" if $plugin_conf_string; + $input .= "https_proxy=$proxy\nhttp_proxy=$proxy\n" if $proxy; PVE::Tools::run_command($cmd, input => $input); -- 2.39.2