public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
* [PATCH manager] fix #5725: pvenode: acme: add options for external account binding
@ 2026-10-04 11:27 Michal Fox
  0 siblings, 0 replies; only message in thread
From: Michal Fox @ 2026-10-04 11:27 UTC (permalink / raw)
  To: pve-devel

The credentials for external account binding can only be entered
interactively when registering an ACME account with pvenode, and only
if the CA requires them or a custom directory was selected. So they
cannot be passed when the account is registered from a script, or
when the directory is passed with --directory and the CA does not
announce that it requires them.

Add the --eab-kid and --eab-hmac-key options, which the API endpoint
already supports, and only ask for the credentials if they were not
passed.

Signed-off-by: Michal Fox <me@dualfroz.com>
---
Tested with mocked API calls: with both options, the credentials are
passed to the API without asking for them, with only one of them the
parameter verification fails, and without them the prompts are the
same as before.

 PVE/CLI/pvenode.pm | 42 ++++++++++++++++++++++++++++--------------
 1 file changed, 28 insertions(+), 14 deletions(-)

diff --git a/PVE/CLI/pvenode.pm b/PVE/CLI/pvenode.pm
index 7f717642..2533a412 100644
--- a/PVE/CLI/pvenode.pm
+++ b/PVE/CLI/pvenode.pm
@@ -89,6 +89,18 @@ __PACKAGE__->register_method({
             directory => get_standard_option('pve-acme-directory-url', {
                     optional => 1,
             }),
+            'eab-kid' => {
+                description => 'Key Identifier for External Account Binding.',
+                type => 'string',
+                requires => 'eab-hmac-key',
+                optional => 1,
+            },
+            'eab-hmac-key' => {
+                description => 'HMAC key for External Account Binding.',
+                type => 'string',
+                requires => 'eab-kid',
+                optional => 1,
+            },
         },
     },
     returns => { type => 'null' },
@@ -144,21 +156,23 @@ __PACKAGE__->register_method({
             print "No Terms of Service found, proceeding.\n";
         }
 
-        my $eab_enabled = $meta->{externalAccountRequired};
-        if (!$eab_enabled && $custom_directory) {
-            my $agreed =
-                PVE::PTY::read_line('Do you want to use external account binding? [y|N]: ');
-            $eab_enabled = ($agreed =~ /^y$/i);
-        } elsif ($eab_enabled) {
-            print "The CA requires external account binding.\n";
-        }
-        if ($eab_enabled) {
-            print "You should have received a key id and a key from your CA.\n";
-            my $eab_kid = PVE::PTY::read_line('Enter EAB key id: ');
-            my $eab_hmac_key = PVE::PTY::read_line('Enter EAB key: ');
+        if (!defined($param->{'eab-kid'})) {
+            my $eab_enabled = $meta->{externalAccountRequired};
+            if (!$eab_enabled && $custom_directory) {
+                my $agreed =
+                    PVE::PTY::read_line('Do you want to use external account binding? [y|N]: ');
+                $eab_enabled = ($agreed =~ /^y$/i);
+            } elsif ($eab_enabled) {
+                print "The CA requires external account binding.\n";
+            }
+            if ($eab_enabled) {
+                print "You should have received a key id and a key from your CA.\n";
+                my $eab_kid = PVE::PTY::read_line('Enter EAB key id: ');
+                my $eab_hmac_key = PVE::PTY::read_line('Enter EAB key: ');
 
-            $param->{'eab-kid'} = $eab_kid;
-            $param->{'eab-hmac-key'} = $eab_hmac_key;
+                $param->{'eab-kid'} = $eab_kid;
+                $param->{'eab-hmac-key'} = $eab_hmac_key;
+            }
         }
 
         print "\nAttempting to register account with '$param->{directory}'..\n";
-- 
2.43.0




^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-04 11:28 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-04 11:27 [PATCH manager] fix #5725: pvenode: acme: add options for external account binding Michal Fox

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal