1
0
Fork 0

LetsEncrypt acme now requires an email and accepting their TOS.

Changes_20.03
Kevin Baensch 3 years ago
parent 8511968173
commit 6379225731
Signed by: derped
GPG Key ID: C0F1D326C7626543
  1. 3
      fn.nix
  2. 17
      services/acme.nix
  3. 1
      services/default.nix

@ -5,6 +5,9 @@ with lib;
rec {
ifelse = a: b: c: if a then b else c;
fileContentsOr = a: b: (ifelse
(pathIsRegularFile a)
a b);
cwd = toString ./.;
lst = { p ? cwd, t ? "regular", b ? false }: (lists.forEach
(attrNames

@ -0,0 +1,17 @@
{ options, config, lib, pkgs, ... }:
with builtins;
with lib;
let
fn = import (../. + (toPath "/fn.nix")) { inherit lib; };
cfg = config.machine;
in mkIf (elem "acme" cfg.services) {
security.acme = {
# see https://letsencrypt.org/repository/
acceptTerms = true;
email = fn.fileContentsOr
(toPath "${cfg.secretPath}/acme.mailAddr")
"${(elemAt cfg.mailAccounts 0).name}@${cfg.domain}";
};
}

@ -1,5 +1,6 @@
{
imports = [
./acme.nix
./cups.nix
./docker.nix
./fail2ban.nix

Loading…
Cancel
Save