feat(hetzner): give stalwart read access to certain keys

This commit is contained in:
2026-08-17 05:26:39 +02:00
parent 38bd5b63f5
commit 75be43140f
2 changed files with 10 additions and 1 deletions
@@ -262,7 +262,12 @@ in {
systemd.services.stalwart-cert-perm = { systemd.services.stalwart-cert-perm = {
description = "Grant stalwart read access to its TLS private key"; description = "Grant stalwart read access to its TLS private key";
after = ["tlsa-update.service" "stalwart.service"]; # Belt-and-suspenders: tlsa-update already chgrps the key after every sync;
# this guarantees the group grant also exists at first boot, before stalwart
# starts (previously ordered after stalwart, so a fresh sync could leave a
# root:root key and webadmin reload would fail with EACCES).
after = ["tlsa-update.service"];
before = ["stalwart.service"];
partOf = ["tlsa-update.service"]; partOf = ["tlsa-update.service"];
wantedBy = ["multi-user.target"]; wantedBy = ["multi-user.target"];
path = [pkgs.coreutils]; path = [pkgs.coreutils];
@@ -33,6 +33,10 @@
# users. # users.
install -D -m 0644 "$SRC_CERT" "$DST_CERT" install -D -m 0644 "$SRC_CERT" "$DST_CERT"
install -D -m 0640 "$SRC_KEY" "$DST_KEY" install -D -m 0640 "$SRC_KEY" "$DST_KEY"
# Stalwart reads the key as user "stalwart" via %{file:...}%; regrant the
# group immediately so every sync leaves it readable (0640 root:stalwart)
# and webadmin config reload never fails with EACCES.
chgrp stalwart "$DST_KEY"
# 2) TLSA 3 1 1 = SHA-256 of the certificate's SubjectPublicKeyInfo (SPKI), # 2) TLSA 3 1 1 = SHA-256 of the certificate's SubjectPublicKeyInfo (SPKI),
# NOT the whole certificate. Matching type 1 = SHA-256 of the SPKI DER. # NOT the whole certificate. Matching type 1 = SHA-256 of the SPKI DER.