summaryrefslogtreecommitdiff
path: root/hostnix/elmo/configuration.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2024-04-24 02:09:31 -0400
committerJoe Mou <dev@mou.fo>2024-04-26 23:54:54 -0400
commit5c0b6b619b2a7ee4502aa66ad8ee03ffff64cacb (patch)
tree8cb4dc00b6afa879fe321fe6d3c7bb1f19daa33b /hostnix/elmo/configuration.nix
parentcce8a71d3192f1ae596e49e86260b8da388e7625 (diff)
ACME with DNS challenge
Diffstat (limited to 'hostnix/elmo/configuration.nix')
-rw-r--r--hostnix/elmo/configuration.nix12
1 files changed, 1 insertions, 11 deletions
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix
index 31cf90b..250cfab 100644
--- a/hostnix/elmo/configuration.nix
+++ b/hostnix/elmo/configuration.nix
@@ -2,6 +2,7 @@
{
imports = [
+ ./acme.nix
./dns.nix
./dyndns.nix
./hardware-configuration.nix
@@ -15,11 +16,6 @@
nix.settings.experimental-features = [ "nix-command" "flakes" ];
- security.acme.acceptTerms = true;
- security.acme.defaults.email = "hostmaster@mou.fo";
- # TODO switch to production certs
- security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
-
security.sudo.wheelNeedsPassword = false;
users.users.joe = {
@@ -60,12 +56,6 @@
recommendedTlsSettings = true;
};
- # TODO remove upon switching to production certs
- services.oauth2_proxy.extraConfig = {
- "ssl-insecure-skip-verify" = true;
- "ssl-upstream-insecure-skip-verify" = true;
- };
-
networking.firewall.allowedTCPPorts = [ 80 443 ];
# This value determines the NixOS release from which the default