about summary refs log tree commit diff
path: root/nixpkgs/nixos/modules/services/system/kerberos/heimdal.nix
blob: 837c59caa5620a874c6c8aa8ca1499d988d33fde (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
{ pkgs, config, lib, ... } :

let
  inherit (lib) mkIf concatStringsSep concatMapStrings toList mapAttrs
    mapAttrsToList;
  cfg = config.services.kerberos_server;
  kerberos = config.krb5.kerberos;
  stateDir = "/var/heimdal";
  aclFiles = mapAttrs
    (name: {acl, ...}: pkgs.writeText "${name}.acl" (concatMapStrings ((
      {principal, access, target, ...} :
      "${principal}\t${concatStringsSep "," (toList access)}\t${target}\n"
    )) acl)) cfg.realms;

  kdcConfigs = mapAttrsToList (name: value: ''
    database = {
      dbname = ${stateDir}/heimdal
      acl_file = ${value}
    }
  '') aclFiles;
  kdcConfFile = pkgs.writeText "kdc.conf" ''
    [kdc]
    ${concatStringsSep "\n" kdcConfigs}
  '';
in

{
  # No documentation about correct triggers, so guessing at them.

  config = mkIf (cfg.enable && kerberos == pkgs.heimdal) {
    systemd.services.kadmind = {
      description = "Kerberos Administration Daemon";
      wantedBy = [ "multi-user.target" ];
      preStart = ''
        mkdir -m 0755 -p ${stateDir}
      '';
      serviceConfig.ExecStart =
        "${kerberos}/libexec/heimdal/kadmind --config-file=/etc/heimdal-kdc/kdc.conf";
      restartTriggers = [ kdcConfFile ];
    };

    systemd.services.kdc = {
      description = "Key Distribution Center daemon";
      wantedBy = [ "multi-user.target" ];
      preStart = ''
        mkdir -m 0755 -p ${stateDir}
      '';
      serviceConfig.ExecStart =
        "${kerberos}/libexec/heimdal/kdc --config-file=/etc/heimdal-kdc/kdc.conf";
      restartTriggers = [ kdcConfFile ];
    };

    systemd.services.kpasswdd = {
      description = "Kerberos Password Changing daemon";
      wantedBy = [ "multi-user.target" ];
      preStart = ''
        mkdir -m 0755 -p ${stateDir}
      '';
      serviceConfig.ExecStart = "${kerberos}/libexec/heimdal/kpasswdd";
      restartTriggers = [ kdcConfFile ];
    };

    environment.etc = {
      # Can be set via the --config-file option to KDC
      "heimdal-kdc/kdc.conf".source = kdcConfFile;
    };
  };
}