diff options
| author | Joe Mou <dev@mou.fo> | 2023-12-21 20:09:41 -0800 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2023-12-22 16:37:20 -0800 |
| commit | d5f787a40b8406c6f20350b2945a741901cefb44 (patch) | |
| tree | a71c6fb0c68a2f7222f6df21cea0eaf47792665a /hostnix/weebnix/configuration.nix | |
| parent | 6e953726913bee6449f8599be1448a33bcb3d177 (diff) | |
Revert "Switch to production ACME certs"
This reverts commit 18148c3dec9154f43c5be6f2ed9e427e990c6a06.
Diffstat (limited to 'hostnix/weebnix/configuration.nix')
| -rw-r--r-- | hostnix/weebnix/configuration.nix | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix index a1c1420..14427f0 100644 --- a/hostnix/weebnix/configuration.nix +++ b/hostnix/weebnix/configuration.nix @@ -18,6 +18,8 @@ security.acme.acceptTerms = true; security.acme.defaults.email = "hostmaster@mou.fo"; + # TODO switch to production certs + security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory"; users.users.joe = { isNormalUser = true; @@ -66,6 +68,12 @@ ''; }; + # TODO remove upon switching to production certs + services.oauth2_proxy.extraConfig = { + "ssl-insecure-skip-verify" = true; + "ssl-upstream-insecure-skip-verify" = true; + }; + networking.firewall.allowedTCPPorts = [ 80 443 ]; # This value determines the NixOS release from which the default |
