public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Michal Fox <me@dualfroz.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH manager] fix #5725: pvenode: acme: add options for external account binding
Date: Sun,  4 Oct 2026 11:27:58 +0000	[thread overview]
Message-ID: <20261004112758.7-1-me@dualfroz.com> (raw)

The credentials for external account binding can only be entered
interactively when registering an ACME account with pvenode, and only
if the CA requires them or a custom directory was selected. So they
cannot be passed when the account is registered from a script, or
when the directory is passed with --directory and the CA does not
announce that it requires them.

Add the --eab-kid and --eab-hmac-key options, which the API endpoint
already supports, and only ask for the credentials if they were not
passed.

Signed-off-by: Michal Fox <me@dualfroz.com>
---
Tested with mocked API calls: with both options, the credentials are
passed to the API without asking for them, with only one of them the
parameter verification fails, and without them the prompts are the
same as before.

 PVE/CLI/pvenode.pm | 42 ++++++++++++++++++++++++++++--------------
 1 file changed, 28 insertions(+), 14 deletions(-)

diff --git a/PVE/CLI/pvenode.pm b/PVE/CLI/pvenode.pm
index 7f717642..2533a412 100644
--- a/PVE/CLI/pvenode.pm
+++ b/PVE/CLI/pvenode.pm
@@ -89,6 +89,18 @@ __PACKAGE__->register_method({
             directory => get_standard_option('pve-acme-directory-url', {
                     optional => 1,
             }),
+            'eab-kid' => {
+                description => 'Key Identifier for External Account Binding.',
+                type => 'string',
+                requires => 'eab-hmac-key',
+                optional => 1,
+            },
+            'eab-hmac-key' => {
+                description => 'HMAC key for External Account Binding.',
+                type => 'string',
+                requires => 'eab-kid',
+                optional => 1,
+            },
         },
     },
     returns => { type => 'null' },
@@ -144,21 +156,23 @@ __PACKAGE__->register_method({
             print "No Terms of Service found, proceeding.\n";
         }
 
-        my $eab_enabled = $meta->{externalAccountRequired};
-        if (!$eab_enabled && $custom_directory) {
-            my $agreed =
-                PVE::PTY::read_line('Do you want to use external account binding? [y|N]: ');
-            $eab_enabled = ($agreed =~ /^y$/i);
-        } elsif ($eab_enabled) {
-            print "The CA requires external account binding.\n";
-        }
-        if ($eab_enabled) {
-            print "You should have received a key id and a key from your CA.\n";
-            my $eab_kid = PVE::PTY::read_line('Enter EAB key id: ');
-            my $eab_hmac_key = PVE::PTY::read_line('Enter EAB key: ');
+        if (!defined($param->{'eab-kid'})) {
+            my $eab_enabled = $meta->{externalAccountRequired};
+            if (!$eab_enabled && $custom_directory) {
+                my $agreed =
+                    PVE::PTY::read_line('Do you want to use external account binding? [y|N]: ');
+                $eab_enabled = ($agreed =~ /^y$/i);
+            } elsif ($eab_enabled) {
+                print "The CA requires external account binding.\n";
+            }
+            if ($eab_enabled) {
+                print "You should have received a key id and a key from your CA.\n";
+                my $eab_kid = PVE::PTY::read_line('Enter EAB key id: ');
+                my $eab_hmac_key = PVE::PTY::read_line('Enter EAB key: ');
 
-            $param->{'eab-kid'} = $eab_kid;
-            $param->{'eab-hmac-key'} = $eab_hmac_key;
+                $param->{'eab-kid'} = $eab_kid;
+                $param->{'eab-hmac-key'} = $eab_hmac_key;
+            }
         }
 
         print "\nAttempting to register account with '$param->{directory}'..\n";
-- 
2.43.0




                 reply	other threads:[~2026-10-04 11:28 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261004112758.7-1-me@dualfroz.com \
    --to=me@dualfroz.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal