summaryrefslogtreecommitdiff
path: root/hostnix/weebnix/configuration.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2023-10-01 14:56:12 -0400
committerJoe Mou <dev@mou.fo>2023-10-01 14:56:43 -0400
commit1facb5ee013282419b8d5629f46acf54b9bb02cc (patch)
treeba14b0535d3bc037943def07116243a39f554c9f /hostnix/weebnix/configuration.nix
parent2f1e0c381e04b25b8c64f260967691f4cf841127 (diff)
Switch to production ACME certs
Diffstat (limited to 'hostnix/weebnix/configuration.nix')
-rw-r--r--hostnix/weebnix/configuration.nix8
1 files changed, 0 insertions, 8 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix
index 0e6591d..1669b8a 100644
--- a/hostnix/weebnix/configuration.nix
+++ b/hostnix/weebnix/configuration.nix
@@ -16,8 +16,6 @@
security.acme.acceptTerms = true;
security.acme.defaults.email = "hostmaster@mou.fo";
- # TODO switch to production certs
- security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
users.users.joe = {
isNormalUser = true;
@@ -82,12 +80,6 @@
'';
};
- # TODO remove upon switching to production certs
- services.oauth2_proxy.extraConfig = {
- "ssl-insecure-skip-verify" = true;
- "ssl-upstream-insecure-skip-verify" = true;
- };
-
networking.firewall.allowedTCPPorts = [ 80 443 ];
# This value determines the NixOS release from which the default