[pmg-devel] [PATCH v2 api/gui/wtk/acme 0/many] Certificates & ACME

Stoiko Ivanov s.ivanov at proxmox.com
Mon Mar 15 19:45:57 CET 2021


huge thanks for the effort and the patches on this long-missing feature in
PMG!

Gave the series a short spin on my test-installs - and it works (mostly)
as advertised) - a few small comments/nits on the individual patches.

Tested with:
* custom cert upload (and removal)
* via powerdns plugin (sadly none of my domain-providers offers API access
  yet)
* the cluster-integration works as I'd expect it


apart from the small glitches:
Tested-By: Stoiko Ivanov <s.ivanov at proxmox.com>
Reviewed-By: Stoiko Ivanov <s.ivanov at proxmox.com>

On Fri, 12 Mar 2021 16:23:49 +0100
Wolfgang Bumiller <w.bumiller at proxmox.com> wrote:

> v2 incorporating feedback from v1
> 
> * api call permission fixups on account methods
> * consistent locking function implementations (without `die $@ if $@`)
> * removed unnecessary call to `sort`
> * cert regex simplification
> * reload/config update code dedup & consistency
> * removed superfluous `border: 0`
> * inlined unnecessary `initComponent`
> 
> and also contains some PVE-compatibility fixes in the acme domain view:
> widget toolkit side should now work seamlessly in the PVE UI code as
> well
> 
> ---
> Original Coverletter:
> 
> These are the pmg-api, pmg-gui and proxmox-widget-toolkit and
> proxmox-acme parts of the ACME series for PMG.
> 
> This requires `pmg-rs` package, which replaces the ACME client from
> `proxmox-acme` and provides the CSR generation and is written in rust.
> Note that the DNS challenge handling still uses proxmox-acme for now.
> 
> proxmox-acme:
>   * Just a `use` statement fixup
>   * Still used for the DNS challenge
> 
> pmg-gui:
>   Just adds the "certificate view", but the real dirt lives in the
>   widget-toolkit.
> 
> proxmox-widget-toolkits:
>   Gets the Certificate, ACME Account, ACME Plugin and ACME Domain view
>   from PVE adapted to be usable for PMG.
>   Changes to PVE are mainly:
>     * API URLs need to be provided since they differ a bit between PVE
>       and PMG.
>     * some additional buttons/fields specific to pmg generated if the
>       parameters for them are present
> 
> pmg-api:
>   Simply gets API entry points for the above. These too are mostly
>   copied from PVE and adapted (also the ACME client API from pmg-rs is slightly
>   different/cleaned up, so that's a minor incompatiblity in some
>   otherwise common code, but a `pve-rs` may fix that). But some things
>   could definitely already go to pve-common (especially schema stuff).
> 
> Note that while I did add the corresponding files to the cluster sync,
> this still needs testing *and* issuing an API certificate may break
> cluster functionality currently. (Stoiko is working on that)
> 
> 
> _______________________________________________
> pmg-devel mailing list
> pmg-devel at lists.proxmox.com
> https://lists.proxmox.com/cgi-bin/mailman/listinfo/pmg-devel
> 
> 





More information about the pmg-devel mailing list