X-Git-Url: http://git.scottworley.com/nixos-make-certs/blobdiff_plain/dad9797b611fc18b5fff3fdaa3fffe0cc012d467..806e2cf3cd14b1489239b216172bbcde08aafd8a:/modules/make-certs.nix?ds=inline diff --git a/modules/make-certs.nix b/modules/make-certs.nix index 812c5a0..53e621f 100644 --- a/modules/make-certs.nix +++ b/modules/make-certs.nix @@ -1,53 +1,76 @@ -{ lib, config, pkgs, ... }: +{ + lib, + config, + pkgs, + ... +}: let - inherit (lib) escapeShellArg; - mkActvationScript = name: cert-cfg: + inherit (lib) escapeShellArg stringAfter; + mkActvationScript = + name: cert-cfg: let pem-path = "${cert-cfg.dir}/${name}.pem"; key-path = "${cert-cfg.dir}/${name}.key"; - in { + in + { name = "make-cert-${name}"; - value = '' - if [[ ! -e ${escapeShellArg pem-path} ]];then - ${pkgs.coreutils}/bin/mkdir -p ${escapeShellArg cert-cfg.dir} - ${pkgs.openssl}/bin/openssl req -batch -x509 -newkey rsa:4096 \ - -keyout ${escapeShellArg key-path} \ - -out ${escapeShellArg pem-path} \ - -days ${escapeShellArg cert-cfg.lifetime} \ - -noenc - ${pkgs.coreutils}/bin/chown ${escapeShellArg cert-cfg.user} ${ - escapeShellArg key-path - } - fi - ''; + value = stringAfter [ "users" ] ( + '' + if [[ ! -e ${escapeShellArg pem-path} ]];then + ${pkgs.coreutils}/bin/mkdir -p ${escapeShellArg cert-cfg.dir} + ${pkgs.openssl}/bin/openssl req -batch -x509 -newkey rsa:4096 \ + -keyout ${escapeShellArg key-path} \ + -out ${escapeShellArg pem-path} \ + -days ${escapeShellArg cert-cfg.lifetime} \ + -noenc + ${pkgs.coreutils}/bin/chown ${escapeShellArg cert-cfg.user} ${escapeShellArg key-path} + fi + '' + + lib.optionalString cert-cfg.print '' + echo Public certificate for ${escapeShellArg name}: >&2 + ${pkgs.coreutils}/bin/cat ${escapeShellArg pem-path} >&2 + '' + ); }; -in { +in +{ options = { chkno.make-certs = lib.mkOption { - type = lib.types.attrsOf (lib.types.submodule { - options = { - dir = lib.mkOption { - type = lib.types.str; - description = "Where to put the certificate and key."; - default = "/secrets"; + description = "Certificates to generate."; + example = { + send-email.user = "stunnel"; + send-print.user = "stunnel"; + }; + type = lib.types.attrsOf ( + lib.types.submodule { + options = { + dir = lib.mkOption { + type = lib.types.str; + description = "Where to put the certificate and key."; + default = "/secrets"; + }; + lifetime = lib.mkOption { + type = lib.types.str; + description = "Lifetime of the generated certificate (in days)."; + # This doesn't yet include any notion of certificate rotation, + # so just make really long-lived certificates for now. + default = "99999"; + }; + print = lib.mkOption { + type = lib.types.bool; + description = "If set, print the certificate (public key) during activation."; + default = false; + }; + user = lib.mkOption { + type = lib.types.str; + description = "The username that owns (can read) the secret key."; + }; }; - lifetime = lib.mkOption { - type = lib.types.str; - description = "Lifetime of the generated certificate (in days)."; - # This doesn't yet include any notion of certificate rotation, - # so just make really long-lived certificates for now. - default = "99999"; - }; - user = lib.mkOption { - type = lib.types.str; - description = "The username that owns (can read) the secret key."; - }; - }; - }); + } + ); }; }; config = { - system.activationScripts = - lib.mapAttrs' mkActvationScript config.chkno.make-certs; + system.activationScripts = lib.mapAttrs' mkActvationScript config.chkno.make-certs; }; }