diff options
Diffstat (limited to 'hostnix/elmo/email.nix')
| -rw-r--r-- | hostnix/elmo/email.nix | 101 |
1 files changed, 101 insertions, 0 deletions
diff --git a/hostnix/elmo/email.nix b/hostnix/elmo/email.nix new file mode 100644 index 0000000..71f85c9 --- /dev/null +++ b/hostnix/elmo/email.nix @@ -0,0 +1,101 @@ +{ config, pkgs, ... }: + +{ + imports = [ ./dyndns.nix ]; + + systemd.tmpfiles.rules = [ + "d /var/lib/postfix/tls 0770 root root" + ]; + + security.acme.certs."${config.networking.fqdn}".postRun = '' + rm -rf /var/lib/postfix/tls/new + mkdir /var/lib/postfix/tls/new + cp -a fullchain.pem key.pem /var/lib/postfix/tls/new/ + systemctl start postfix-tls-rotate + ''; + + systemd.services.postfix-tls-rotate = { + requires = [ "network-online.target" ]; + after = [ "network-online.target" ]; + unitConfig = { + OnFailure = "status-email@%n.service"; + }; + serviceConfig = { + Type = "oneshot"; + # Not really necessary indirection but interesting to try out. Note we + # must run as root (not DynamicUser) to run systemctl. + LoadCredential = [ "dyndns:/var/secrets/dyndns/" ]; + }; + environment = { + "DYNDNS" = "%d/dyndns"; + }; + script = '' + cd /var/lib/postfix/tls + + publish() { + fqdn=${config.networking.fqdn} + tlsfps_fqdn=_tlsfps.''${fqdn%%.*}.dynamic.''${fqdn#*.} + + ${pkgs.dnsutils}/bin/nsupdate -v -k ''${DYNDNS}_$(< ''${DYNDNS}_basename).private <<. + update delete $tlsfps_fqdn. TXT + $( + for cert in */fullchain.pem; do + echo -n "update add $tlsfps_fqdn. 300 TXT " + ${pkgs.openssl}/bin/openssl x509 -noout -fingerprint -sha256 -in "$cert" | cut -d= -f2 + done + ) + send + . + } + + # If a certificate is next, we must have been invoked by our timer; + # rotate it to live. + if [[ -d next ]]; then + rm -rf prev + mv live prev + mv next live + systemctl reload postfix + # If a certificate is new then publish it. + elif [[ -d new ]]; then + publish + # We'll run again in at least an hour, after the postfix master picks up + # the new TLS fingerprints. But if this is the first run (there are no + # live certificates), rotate immediately. + if [[ -d live ]]; then + mv new next + else + mv new live + systemctl reload postfix + fi + fi + ''; + }; + + systemd.timers.postfix-tls-rotate = { + wantedBy = [ "multi-user.target" ]; + timerConfig = { + OnBootSec = "2h"; + OnUnitInactiveSec = "2h"; + }; + }; + + services.postfix = { + enable = true; + extraAliases = '' + root: joe + joe: joe@mou.fo + ''; + settings.main = { + myhostname = config.networking.fqdn; + relayhost = [ "smtp.mou.fo:587" ]; + smtp_tls_chain_files = [ + "/var/lib/postfix/tls/live/key.pem" + "/var/lib/postfix/tls/live/fullchain.pem" + ]; + smtp_tls_security_level = "encrypt"; + smtp_tls_session_cache_database = "btree:\${data_directory}/smtp_scache"; + message_size_limit = 51200000; + default_destination_rate_delay = "1s"; + }; + }; +} |
