Optionally allow for setting external account binding credentials at the account registration endpoint.
Signed-off-by: Folke Gleumes <f.gleu...@proxmox.com> --- src/acme/client.rs | 7 +++++- src/api2/config/acme.rs | 35 +++++++++++++++++++++++--- src/bin/proxmox_backup_manager/acme.rs | 12 ++++++--- 3 files changed, 47 insertions(+), 7 deletions(-) diff --git a/src/acme/client.rs b/src/acme/client.rs index 46566210..1396eb2c 100644 --- a/src/acme/client.rs +++ b/src/acme/client.rs @@ -116,6 +116,7 @@ impl AcmeClient { tos_agreed: bool, contact: Vec<String>, rsa_bits: Option<u32>, + eab_creds: Option<(String, String)>, ) -> Result<&'a Account, anyhow::Error> { self.tos = if tos_agreed { self.terms_of_service_url().await?.map(str::to_owned) @@ -123,10 +124,14 @@ impl AcmeClient { None }; - let account = Account::creator() + let mut account = Account::creator() .set_contacts(contact) .agree_to_tos(tos_agreed); + if let Some((eab_kid, eab_hmac_key)) = eab_creds { + account = account.set_eab_credentials(eab_kid, eab_hmac_key)?; + } + let account = if let Some(bits) = rsa_bits { account.generate_rsa_key(bits)? } else { diff --git a/src/api2/config/acme.rs b/src/api2/config/acme.rs index 1954318b..8f010027 100644 --- a/src/api2/config/acme.rs +++ b/src/api2/config/acme.rs @@ -182,6 +182,16 @@ fn account_contact_from_string(s: &str) -> Vec<String> { description: "The ACME Directory.", optional: true, }, + eab_kid: { + type: String, + description: "Key Identifier for External Account Binding.", + optional: true, + }, + eab_hmac_key: { + type: String, + description: "HMAC Key for External Account Binding.", + optional: true, + } }, }, access: { @@ -196,6 +206,8 @@ fn register_account( contact: String, tos_url: Option<String>, directory: Option<String>, + eab_kid: Option<String>, + eab_hmac_key: Option<String>, rpcenv: &mut dyn RpcEnvironment, ) -> Result<String, Error> { let auth_id: Authid = rpcenv.get_auth_id().unwrap().parse()?; @@ -204,6 +216,15 @@ fn register_account( AcmeAccountName::from_string_unchecked("default".to_string()) }); + // TODO: this should be done via the api definition, but + // the api macro currently lacks this ability (2023-11-06) + if eab_kid.is_some() ^ eab_hmac_key.is_some() { + http_bail!( + BAD_REQUEST, + "either both or none of 'eab_kid' and 'eab_hmac_key' have to be set." + ); + } + if Path::new(&crate::config::acme::account_path(&name)).exists() { http_bail!(BAD_REQUEST, "account {} already exists", name); } @@ -224,8 +245,15 @@ fn register_account( task_log!(worker, "Registering ACME account '{}'...", &name); - let account = - do_register_account(&mut client, &name, tos_url.is_some(), contact, None).await?; + let account = do_register_account( + &mut client, + &name, + tos_url.is_some(), + contact, + None, + eab_kid.zip(eab_hmac_key), + ) + .await?; task_log!( worker, @@ -244,10 +272,11 @@ pub async fn do_register_account<'a>( agree_to_tos: bool, contact: String, rsa_bits: Option<u32>, + eab_creds: Option<(String, String)>, ) -> Result<&'a Account, Error> { let contact = account_contact_from_string(&contact); client - .new_account(name, agree_to_tos, contact, rsa_bits) + .new_account(name, agree_to_tos, contact, rsa_bits, eab_creds) .await } diff --git a/src/bin/proxmox_backup_manager/acme.rs b/src/bin/proxmox_backup_manager/acme.rs index de48a420..17ca5958 100644 --- a/src/bin/proxmox_backup_manager/acme.rs +++ b/src/bin/proxmox_backup_manager/acme.rs @@ -156,9 +156,15 @@ async fn register_account( println!("Attempting to register account with {:?}...", directory); - let account = - api2::config::acme::do_register_account(&mut client, &name, tos_agreed, contact, None) - .await?; + let account = api2::config::acme::do_register_account( + &mut client, + &name, + tos_agreed, + contact, + None, + None, + ) + .await?; println!("Registration successful, account URL: {}", account.location); -- 2.39.2 _______________________________________________ pve-devel mailing list pve-devel@lists.proxmox.com https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel