From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 87EFF1FF0AA for ; Tue, 06 Oct 2026 14:31:59 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 756AD215ED; Tue, 06 Oct 2026 14:31:42 +0200 (CEST) From: David Riley To: pve-devel@lists.proxmox.com Subject: [PATCH common/manager 0/2] fix #8006: acme: lifetime-based certificate renewal threshold Date: Tue, 6 Oct 2026 14:31:18 +0200 Message-ID: <20261006123120.68750-1-d.riley@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791289892537 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.765 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: EXR4QICILESSBAXO22YA4CRLPBCRPBAX X-Message-ID-Hash: EXR4QICILESSBAXO22YA4CRLPBCRPBAX X-MailFrom: d.riley@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: This patch series addresses an issue where short-lived ACME certificates (e.g., 31-day validity) trigger daily renewal attempts due to PVE's hardcoded 30-day threshold. Because PVE currently relies on non-ARI renewal logic, these daily attempts quickly exhaust upstream rate limits. With Let's Encrypt, for example, this would hit their duplicate certificate limit (5 renewals per exact set of identifiers per 7 days) [0], resulting in blocked issuances. To prevent hitting these upstream limits, the static threshold is replaced with a dynamic one based on the certificate's actual lifetime (notAfter - notBefore) [1]. The scaling mirrors the logic already present in Proxmox Backup Server [2]. This is intended as a stop-gap measure to gracefully handle the shift toward shorter-lived certificates until the full ACME Renewal Information (ARI) [3] flow is implemented. Link: https://bugzilla.proxmox.com/show_bug.cgi?id=8006 [0] https://letsencrypt.org/docs/rate-limits/#new-certificates-per-exact-set-of-identifiers [1] https://www.cs.auckland.ac.nz/~pgut001/pubs/x509guide.txt [2] https://lore.proxmox.com/pbs-devel/20260423134607.105229-2-m.federanko@proxmox.com/ [3] https://www.rfc-editor.org/rfc/rfc9773.html pve-common: David Riley (1): certificate: add helpers for lifetime-based ACME renewal src/PVE/Certificate.pm | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) pve-manager: David Riley (1): fix #8006: api: acme: lifetime-based certificate renewal threshold PVE/API2/ACME.pm | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) Summary over all repositories: 2 files changed, 36 insertions(+), 2 deletions(-) -- Generated by murpp 0.11.0