Repository navigation
Commit 3e5d570
security/acme-client: add JetKVM automation via acme.sh deploy hook
Adds "Upload certificate to JetKVM (SSH)" (acme_jetkvm), a thin wrapper
around the acme.sh "jetkvm" deploy hook (acmesh-official/acme.sh#7254),
following the exact pattern already used by AcmeFritzbox/AcmePanos/
AcmeZyxelGs1900/etc.: set a few DEPLOY_JETKVM_* env vars from the
automation's config and let LeAutomation\Base::runAcme() invoke
`acme.sh --deploy --deploy-hook jetkvm`.
This is the "much smaller follow-up PR" requested by the maintainer on
opnsense#5621 in place of that PR's full custom PHP
implementation (own SSH exec session, own atomic-write logic, its own
API controller/configd actions) -- all of that now lives once in the
acme.sh hook instead of being duplicated here.
Exposes only what a user needs to fill in: host, username (default
root), port (default 22), and a "Reboot After Upload" checkbox (default
checked) that maps to the hook's DEPLOY_JETKVM_RESTART_CMD ("reboot" or
"none") -- narrower than the hook's own free-text restart command, kept
consistent with AcmeZyxelGs1900's equivalent checkbox. Everything else
(remote path, filenames, permissions, the HTTPS-mode precondition
check) uses the hook's own defaults.
Unlike the old SFTP/remote-SSH-style automations, this one does not use
the plugin's own managed SSH identity/known_hosts store (no "Show
Identity" button) -- acme.sh's own deploy hooks assume SSH access is
already configured on the host, same as every other Acme* automation in
this plugin. The firewall's own root SSH key needs to already be
trusted by the JetKVM device.
Field names cross-checked between the model, dialog, and PHP class;
LeAutomationFactory's type-to-classname derivation confirmed to resolve
"acme_jetkvm" to AcmeJetkvm; xmllint --noout clean on both changed XML
files; php -l clean on the new class. BooleanField comparison for
"Reboot After Upload" uses loose == 1, matching the house idiom already
used by AcmeZyxelGs1900/AcmeVault for the same pattern.
acme_jetkvm_host is Required N in the model, matching every other
Acme*_host/url field in this plugin (acme_fritzbox_url, acme_panos_host,
acme_zyxel_gs1900_host, etc. are all Required N too) -- so this doesn't
deviate from house style. But unlike those, a blank JetKVM host isn't
harmless: jetkvm.sh falls back to the certificate's own domain name as
the SSH target, which will almost never be the device. prepare() now
follows ConfigdGeneric's own precedent (check the field, log_error, and
return false to stop the automation) rather than adding a new pattern.
Validated end-to-end on a real OPNsense 26.7 box against a real JetKVM
device: locally-built test packages (os-acme-client + acme.sh, each
adding only the JetKVM-related file(s) on top of the currently
published packages -- see pkg-test/ in the delivery repo) were
installed so this automation could invoke a real deploy/jetkvm.sh.
Confirmed working end to end: issuance -> this automation -> the
acme.sh hook -> upload -> HTTPS-mode check -> reboot -> certificate
served by the device. That run predates the empty-host check added
above, so the check itself has only been exercised with php -l, not
against real hardware. Not yet testable against a *stock* OPNsense
install, since that still requires acmesh-official/acme.sh#7254 to
merge and the FreeBSD acme.sh port to pick it up.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M7rTpUF3btoBXSZ95Psjh71 parent acb1d44 commit 3e5d570
5 files changed
Lines changed: 121 additions & 1 deletion
File tree
- security/acme-client
- src/opnsense/mvc/app
- controllers/OPNsense/AcmeClient/forms
- library/OPNsense/AcmeClient/LeAutomation
- models/OPNsense/AcmeClient
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
11 | 17 | | |
12 | 18 | | |
13 | 19 | | |
| |||
Lines changed: 39 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
515 | 515 | | |
516 | 516 | | |
517 | 517 | | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
| 540 | + | |
| 541 | + | |
| 542 | + | |
| 543 | + | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
| 556 | + | |
518 | 557 | | |
Lines changed: 57 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
Lines changed: 18 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1449 | 1449 | | |
1450 | 1450 | | |
1451 | 1451 | | |
| 1452 | + | |
1452 | 1453 | | |
1453 | 1454 | | |
1454 | 1455 | | |
| |||
1842 | 1843 | | |
1843 | 1844 | | |
1844 | 1845 | | |
| 1846 | + | |
| 1847 | + | |
| 1848 | + | |
| 1849 | + | |
| 1850 | + | |
| 1851 | + | |
| 1852 | + | |
| 1853 | + | |
| 1854 | + | |
| 1855 | + | |
| 1856 | + | |
| 1857 | + | |
| 1858 | + | |
| 1859 | + | |
| 1860 | + | |
| 1861 | + | |
| 1862 | + | |
1845 | 1863 | | |
1846 | 1864 | | |
1847 | 1865 | | |
| |||
0 commit comments