{ config, pkgs, ... }: { imports = [ ./dyndns.nix ]; systemd.tmpfiles.rules = [ "d /var/lib/postfix/tls 0770 root root" ]; security.acme.certs."${config.networking.fqdn}".postRun = '' rm -rf /var/lib/postfix/tls/new mkdir /var/lib/postfix/tls/new cp -a fullchain.pem key.pem /var/lib/postfix/tls/new/ systemctl start postfix-tls-rotate ''; systemd.services.postfix-tls-rotate = { requires = [ "network-online.target" ]; after = [ "network-online.target" ]; unitConfig = { OnFailure = "status-email@%n.service"; }; serviceConfig = { Type = "oneshot"; # Not really necessary indirection but interesting to try out. Note we # must run as root (not DynamicUser) to run systemctl. LoadCredential = [ "dyndns:/var/secrets/dyndns/" ]; }; environment = { "DYNDNS" = "%d/dyndns"; }; script = '' cd /var/lib/postfix/tls publish() { fqdn=${config.networking.fqdn} tlsfps_fqdn=_tlsfps.''${fqdn%%.*}.dynamic.''${fqdn#*.} ${pkgs.dnsutils}/bin/nsupdate -v -k ''${DYNDNS}_$(< ''${DYNDNS}_basename).private <<. update delete $tlsfps_fqdn. TXT $( for cert in */fullchain.pem; do echo -n "update add $tlsfps_fqdn. 300 TXT " ${pkgs.openssl}/bin/openssl x509 -noout -fingerprint -sha256 -in "$cert" | cut -d= -f2 done ) send . } # If a certificate is next, we must have been invoked by our timer; # rotate it to live. if [[ -d next ]]; then rm -rf prev mv live prev mv next live systemctl reload postfix # If a certificate is new then publish it. elif [[ -d new ]]; then publish # We'll run again in at least an hour, after the postfix master picks up # the new TLS fingerprints. But if this is the first run (there are no # live certificates), rotate immediately. if [[ -d live ]]; then mv new next else mv new live systemctl reload postfix fi fi ''; }; systemd.timers.postfix-tls-rotate = { wantedBy = [ "multi-user.target" ]; timerConfig = { OnBootSec = "2h"; OnUnitInactiveSec = "2h"; }; }; services.postfix = { enable = true; hostname = config.networking.fqdn; relayHost = "smtp.mou.fo"; relayPort = 587; sslCert = "/var/lib/postfix/tls/live/fullchain.pem"; sslKey = "/var/lib/postfix/tls/live/key.pem"; extraAliases = '' root: joe joe: joe@mou.fo ''; config = { smtp_tls_security_level = "encrypt"; smtp_tls_session_cache_database = "btree:\${data_directory}/smtp_scache"; message_size_limit = "51200000"; default_destination_rate_delay = "1s"; }; }; }