2017-11-06 17:41:34 +00:00
|
|
|
{ pkgs, config, lib, ... } :
|
|
|
|
|
|
|
|
let
|
2017-11-13 13:09:35 +00:00
|
|
|
inherit (lib) mkIf concatStringsSep concatMapStrings toList mapAttrs
|
2019-06-16 20:59:06 +01:00
|
|
|
mapAttrsToList;
|
2017-11-06 17:41:34 +00:00
|
|
|
cfg = config.services.kerberos_server;
|
|
|
|
kerberos = config.krb5.kerberos;
|
|
|
|
stateDir = "/var/heimdal";
|
2017-11-13 13:09:35 +00:00
|
|
|
aclFiles = mapAttrs
|
|
|
|
(name: {acl, ...}: pkgs.writeText "${name}.acl" (concatMapStrings ((
|
|
|
|
{principal, access, target, ...} :
|
|
|
|
"${principal}\t${concatStringsSep "," (toList access)}\t${target}\n"
|
|
|
|
)) acl)) cfg.realms;
|
2017-11-06 17:41:34 +00:00
|
|
|
|
2017-11-13 13:09:35 +00:00
|
|
|
kdcConfigs = mapAttrsToList (name: value: ''
|
2017-11-06 17:41:34 +00:00
|
|
|
database = {
|
|
|
|
dbname = ${stateDir}/heimdal
|
2017-11-13 13:09:35 +00:00
|
|
|
acl_file = ${value}
|
2017-11-06 17:41:34 +00:00
|
|
|
}
|
2017-11-13 13:09:35 +00:00
|
|
|
'') aclFiles;
|
2017-11-06 17:41:34 +00:00
|
|
|
kdcConfFile = pkgs.writeText "kdc.conf" ''
|
|
|
|
[kdc]
|
|
|
|
${concatStringsSep "\n" kdcConfigs}
|
|
|
|
'';
|
|
|
|
in
|
|
|
|
|
|
|
|
{
|
|
|
|
# No documentation about correct triggers, so guessing at them.
|
|
|
|
|
|
|
|
config = mkIf (cfg.enable && kerberos == pkgs.heimdalFull) {
|
|
|
|
systemd.services.kadmind = {
|
|
|
|
description = "Kerberos Administration Daemon";
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
|
|
|
preStart = ''
|
|
|
|
mkdir -m 0755 -p ${stateDir}
|
|
|
|
'';
|
|
|
|
serviceConfig.ExecStart =
|
|
|
|
"${kerberos}/libexec/heimdal/kadmind --config-file=/etc/heimdal-kdc/kdc.conf";
|
2017-11-13 13:09:35 +00:00
|
|
|
restartTriggers = [ kdcConfFile ];
|
2017-11-06 17:41:34 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
systemd.services.kdc = {
|
|
|
|
description = "Key Distribution Center daemon";
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
|
|
|
preStart = ''
|
|
|
|
mkdir -m 0755 -p ${stateDir}
|
|
|
|
'';
|
|
|
|
serviceConfig.ExecStart =
|
|
|
|
"${kerberos}/libexec/heimdal/kdc --config-file=/etc/heimdal-kdc/kdc.conf";
|
|
|
|
restartTriggers = [ kdcConfFile ];
|
|
|
|
};
|
|
|
|
|
|
|
|
systemd.services.kpasswdd = {
|
|
|
|
description = "Kerberos Password Changing daemon";
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
|
|
|
preStart = ''
|
|
|
|
mkdir -m 0755 -p ${stateDir}
|
|
|
|
'';
|
|
|
|
serviceConfig.ExecStart = "${kerberos}/libexec/heimdal/kpasswdd";
|
2017-11-13 13:09:35 +00:00
|
|
|
restartTriggers = [ kdcConfFile ];
|
2017-11-06 17:41:34 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
environment.etc = {
|
|
|
|
# Can be set via the --config-file option to KDC
|
|
|
|
"heimdal-kdc/kdc.conf".source = kdcConfFile;
|
2017-11-13 13:09:35 +00:00
|
|
|
};
|
2017-11-06 17:41:34 +00:00
|
|
|
};
|
|
|
|
}
|