Hello,
i encounter some difficulty, I'm ussing smallstep PKI, Certificate generate via ACME or CLI, none of certificate works with pveproxy .
proxmox 8.x & version 9.2.20 same problem
I try to adapt some x509 Extensions to certificate and nothing change. I'm stuck
I Looked for similar error, MTU is default(1500), for the second param with ACME.pm patch, and to others interfaces, i got exactly same problem.
Certificate generated are validated with openssl verify and works with others nginx ssl app.
Any Suggestions?
Thanks in advance,
Flavinux
i encounter some difficulty, I'm ussing smallstep PKI, Certificate generate via ACME or CLI, none of certificate works with pveproxy .
proxmox 8.x & version 9.2.20 same problem
Code:
# pveproxy start --debug
2026-10-03 18:19:09.349072 worker[1658055]: PVE::APIServer::AnyEvent +1937: (eval): ACCEPT FH10 CONN1
2026-10-03 18:19:09.349072 worker[1658056]: PVE::APIServer::AnyEvent +1937: (eval): ACCEPT FH10 CONN1
2026-10-03 18:19:09.349168 worker[1658055]: PVE::APIServer::AnyEvent +1937: (eval): Setting TLS to autostart
2026-10-03 18:19:09.349170 worker[1658056]: PVE::APIServer::AnyEvent +1937: (eval): Setting TLS to autostart
2026-10-03 18:19:09.350017 worker[1658056]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: close connection AnyEvent::Handle=HASH(0x62340a4fd900)
2026-10-03 18:19:09.350017 worker[1658055]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: close connection AnyEvent::Handle=HASH(0x62340a4fd900)
2026-10-03 18:19:09.350082 worker[1658056]: PVE::APIServer::AnyEvent +178: __ANON__: CLOSE FH10
2026-10-03 18:19:09.350082 worker[1658055]: PVE::APIServer::AnyEvent +178: __ANON__: CLOSE FH10
2026-10-03 18:19:09.350150 worker[1658056]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: DISCONNECT CONN0
2026-10-03 18:19:09.350153 worker[1658055]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: DISCONNECT CONN0
2026-10-03 18:19:09.369257 worker[1658056]: PVE::APIServer::AnyEvent +1937: (eval): ACCEPT FH10 CONN1
2026-10-03 18:19:09.369257 worker[1658057]: PVE::APIServer::AnyEvent +1937: (eval): ACCEPT FH10 CONN1
2026-10-03 18:19:09.369315 worker[1658056]: PVE::APIServer::AnyEvent +1937: (eval): Setting TLS to autostart
2026-10-03 18:19:09.369316 worker[1658057]: PVE::APIServer::AnyEvent +1937: (eval): Setting TLS to autostart
2026-10-03 18:19:09.369767 worker[1658056]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: close connection AnyEvent::Handle=HASH(0x62341101f690)
2026-10-03 18:19:09.369767 worker[1658057]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: close connection AnyEvent::Handle=HASH(0x62341102cef0)
2026-10-03 18:19:09.369819 worker[1658056]: PVE::APIServer::AnyEvent +178: __ANON__: CLOSE FH10
2026-10-03 18:19:09.369819 worker[1658057]: PVE::APIServer::AnyEvent +178: __ANON__: CLOSE FH10
2026-10-03 18:19:09.369870 worker[1658056]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: DISCONNECT CONN0
2026-10-03 18:19:09.369873 worker[1658057]: PVE::APIServer::AnyEvent +1988: client_do_disconnect: DISCONNECT CONN0
Code:
openssl s_client -connect pve.domain.tld:8006 -showcerts
Connecting to 2001:0DB8::174
CONNECTED(00000003)
805784DB457D0000:error:0A000126:SSL routines::unexpected eof while reading:../ssl/record/rec_layer_s3.c:698:
---
no peer certificate available
---
No client certificate CA names sent
Negotiated TLS1.3 group: <NULL>
---
SSL handshake has read 0 bytes and written 1580 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Protocol: TLSv1.3
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
Code:
With curl:
curl -v -k https://pve.domain.tld:8006/
* Host pve.domain.tld:8006 was resolved.
* IPv6: 2001:0DB8::174
* IPv4: 192.168.0.174
* Trying [2001:0DB8::174]:8006...
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (OUT), TLS alert, decode error (562):
* TLS connect error: error:0A000126:SSL routines::unexpected eof while reading
* closing connection #0
Code:
pveversion -v
proxmox-ve: 9.2.0 (running kernel: 7.0.14-16-pve)
pve-manager: 9.2.20 (running version: 9.2.20/49318c671b82f31e)
proxmox-kernel-helper: 9.2.0
proxmox-kernel-7.0.14-19-pve-signed: 7.0.14-19
proxmox-kernel-7.0: 7.0.14-19
proxmox-kernel-7.0.14-16-pve-signed: 7.0.14-16
proxmox-kernel-7.0.14-15-pve-signed: 7.0.14-15
proxmox-kernel-7.0.14-14-pve-signed: 7.0.14-14
pve-kernel-5.11: 7.0-10
proxmox-kernel-6.8.12-43-pve-signed: 6.8.12-43
proxmox-kernel-6.8: 6.8.12-43
proxmox-kernel-6.8.12-41-pve-signed: 6.8.12-41
proxmox-kernel-6.5.13-6-pve-signed: 6.5.13-6
proxmox-kernel-6.5: 6.5.13-6
pve-kernel-5.13.19-2-pve: 5.13.19-4
pve-kernel-5.11.22-7-pve: 5.11.22-12
pve-kernel-5.11.22-1-pve: 5.11.22-2
ceph-fuse: 19.2.6-pve4
corosync: 3.1.10-pve3
criu: 4.1.1-1
frr-pythontools: 10.6.1-1+pve3
ifupdown2: 3.3.0-1+pmx12
intel-microcode: 3.20251111.1~deb13u1
ksm-control-daemon: 1.5-1
libjs-extjs: 7.0.0-7
libproxmox-acme-perl: 1.7.2
libproxmox-backup-qemu0: 2.0.3
libproxmox-rs-perl: 0.4.1
libpve-access-control: 9.1.2
libpve-apiclient-perl: 3.4.3
libpve-cluster-api-perl: 9.1.6
libpve-cluster-perl: 9.1.6
libpve-common-perl: 9.2.2
libpve-guest-common-perl: 6.0.5
libpve-http-server-perl: 6.0.5
libpve-network-perl: 1.6.7
libpve-notify-perl: 9.1.6
libpve-rs-perl: 0.15.3
libpve-storage-perl: 9.1.10
libspice-server1: 0.15.2-1+b1
lvm2: 2.03.31-2+pmx1
lxc-pve: 7.0.0-2
lxcfs: 7.0.0-pve1
novnc-pve: 1.7.0-2
openvswitch-switch: 3.5.0-1+b1
proxmox-backup-client: 4.2.6-1
proxmox-backup-file-restore: 4.2.6-1
proxmox-backup-restore-image: 1.0.0
proxmox-enterprise-support-keyring: 1.1
proxmox-firewall: 1.2.3
proxmox-kernel-helper: 9.2.0
proxmox-mail-forward: 1.0.3
proxmox-mini-journalreader: 1.7
proxmox-offline-mirror-helper: 0.7.4
proxmox-widget-toolkit: 5.2.10
pve-cluster: 9.1.6
pve-container: 6.1.14
pve-docs: 9.2.12
pve-edk2-firmware: 4.2026.08-1
pve-esxi-import-tools: 1.0.1
pve-firewall: 6.0.6
pve-firmware: 3.18-6
pve-ha-manager: 5.2.5
pve-i18n: 3.10.0
pve-qemu-kvm: 11.0.3-3
pve-xtermjs: 6.0.0-2
qemu-server: 9.2.8
smartmontools: 7.5-pve2
spiceterm: 3.4.2
swtpm: 0.8.0+pve3
vncterm: 1.9.2
zfsutils-linux: 2.4.4-pve1
I try to adapt some x509 Extensions to certificate and nothing change. I'm stuck
I Looked for similar error, MTU is default(1500), for the second param with ACME.pm patch, and to others interfaces, i got exactly same problem.
Certificate generated are validated with openssl verify and works with others nginx ssl app.
Any Suggestions?
Thanks in advance,
Flavinux