Skip to main content

Module upstream

Module upstream 

Source
Expand description

acme-proxy upstream … — managing this server’s own ACME account at the upstream CA, when the relay signer backend is in use.

§Why this command exists alongside signer.relay.eab

An upstream that requires External Account Binding hands the operator a kid and an HMAC secret out of band. That credential authorizes exactly one thing — a single newAccount call — and is useless afterwards. This command takes the secret on stdin (or from a file), uses it once, and never writes it anywhere — no bootstrap secret is left readable on disk for the life of the server, unlike the alternative of setting signer.relay.eab in configuration (see acme_proxy_core::config::RelayEabConfig), which trades that property away for not needing this separate step. The secret is deliberately not accepted as a command-line flag either way: argv is visible to every process on the host via ps and is routinely written to shell history.

Enums§

UpstreamCommand
UpstreamOrderCommand

Functions§

run_upstream_command
Resolves which profile’s [signer.relay] a command should act on.