From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 5F8121FF0AD for ; Sun, 04 Oct 2026 13:28:15 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 35942215CC; Sun, 04 Oct 2026 13:28:12 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dualfroz.com; s=dkim; t=1791113280; h=from:subject:date:message-id:to:mime-version: content-transfer-encoding; bh=p5xn6jyg5sL7hBOHw2cj+Te6dLuQ6vWJujzMmFPdScs=; b=0GMUxWv4azjDO7MpTdQJDH2QegjuMa4nGB142XOlpoQtbY/yZv3J4mipGqkifbcOqV+Eqb 1mIuUXA2xDkWYwHb2QWVUOxfh94xfw7eG5oBNTuI+VcM/MwU1isg28SOhBzZW348tM2tgX WdN3/0Cd59lqcyd6xxFB1q1M7UT31CTttd3fwfqRZWYIPOpjNZukgatYo6TZCP3h2/PpIn Obr1jtJAqYeyXBGYCW/ZGggLHFYb9XpCz6Cu+MjfVE4DqKUszRE3K4WODATn1YTW8p+iqc N4XcrZPSO7dRdTRLDTYZN9yNvpuiRo/bh+NRSPJvR7WvPYPeCk0Q8podXCfYeQ== From: Michal Fox To: pve-devel@lists.proxmox.com Subject: [PATCH manager] fix #5725: pvenode: acme: add options for external account binding Date: Sun, 4 Oct 2026 11:27:58 +0000 Message-ID: <20261004112758.7-1-me@dualfroz.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.229 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: YFJC6DFNOHJTFSLSHDNQUONE3UMZCPWR X-Message-ID-Hash: YFJC6DFNOHJTFSLSHDNQUONE3UMZCPWR X-MailFrom: me@dualfroz.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The credentials for external account binding can only be entered interactively when registering an ACME account with pvenode, and only if the CA requires them or a custom directory was selected. So they cannot be passed when the account is registered from a script, or when the directory is passed with --directory and the CA does not announce that it requires them. Add the --eab-kid and --eab-hmac-key options, which the API endpoint already supports, and only ask for the credentials if they were not passed. Signed-off-by: Michal Fox --- Tested with mocked API calls: with both options, the credentials are passed to the API without asking for them, with only one of them the parameter verification fails, and without them the prompts are the same as before. PVE/CLI/pvenode.pm | 42 ++++++++++++++++++++++++++++-------------- 1 file changed, 28 insertions(+), 14 deletions(-) diff --git a/PVE/CLI/pvenode.pm b/PVE/CLI/pvenode.pm index 7f717642..2533a412 100644 --- a/PVE/CLI/pvenode.pm +++ b/PVE/CLI/pvenode.pm @@ -89,6 +89,18 @@ __PACKAGE__->register_method({ directory => get_standard_option('pve-acme-directory-url', { optional => 1, }), + 'eab-kid' => { + description => 'Key Identifier for External Account Binding.', + type => 'string', + requires => 'eab-hmac-key', + optional => 1, + }, + 'eab-hmac-key' => { + description => 'HMAC key for External Account Binding.', + type => 'string', + requires => 'eab-kid', + optional => 1, + }, }, }, returns => { type => 'null' }, @@ -144,21 +156,23 @@ __PACKAGE__->register_method({ print "No Terms of Service found, proceeding.\n"; } - my $eab_enabled = $meta->{externalAccountRequired}; - if (!$eab_enabled && $custom_directory) { - my $agreed = - PVE::PTY::read_line('Do you want to use external account binding? [y|N]: '); - $eab_enabled = ($agreed =~ /^y$/i); - } elsif ($eab_enabled) { - print "The CA requires external account binding.\n"; - } - if ($eab_enabled) { - print "You should have received a key id and a key from your CA.\n"; - my $eab_kid = PVE::PTY::read_line('Enter EAB key id: '); - my $eab_hmac_key = PVE::PTY::read_line('Enter EAB key: '); + if (!defined($param->{'eab-kid'})) { + my $eab_enabled = $meta->{externalAccountRequired}; + if (!$eab_enabled && $custom_directory) { + my $agreed = + PVE::PTY::read_line('Do you want to use external account binding? [y|N]: '); + $eab_enabled = ($agreed =~ /^y$/i); + } elsif ($eab_enabled) { + print "The CA requires external account binding.\n"; + } + if ($eab_enabled) { + print "You should have received a key id and a key from your CA.\n"; + my $eab_kid = PVE::PTY::read_line('Enter EAB key id: '); + my $eab_hmac_key = PVE::PTY::read_line('Enter EAB key: '); - $param->{'eab-kid'} = $eab_kid; - $param->{'eab-hmac-key'} = $eab_hmac_key; + $param->{'eab-kid'} = $eab_kid; + $param->{'eab-hmac-key'} = $eab_hmac_key; + } } print "\nAttempting to register account with '$param->{directory}'..\n"; -- 2.43.0