feat(hetzner): give stalwart read access to certain keys
This commit is contained in:
@@ -262,7 +262,12 @@ in {
|
|||||||
|
|
||||||
systemd.services.stalwart-cert-perm = {
|
systemd.services.stalwart-cert-perm = {
|
||||||
description = "Grant stalwart read access to its TLS private key";
|
description = "Grant stalwart read access to its TLS private key";
|
||||||
after = ["tlsa-update.service" "stalwart.service"];
|
# Belt-and-suspenders: tlsa-update already chgrps the key after every sync;
|
||||||
|
# this guarantees the group grant also exists at first boot, before stalwart
|
||||||
|
# starts (previously ordered after stalwart, so a fresh sync could leave a
|
||||||
|
# root:root key and webadmin reload would fail with EACCES).
|
||||||
|
after = ["tlsa-update.service"];
|
||||||
|
before = ["stalwart.service"];
|
||||||
partOf = ["tlsa-update.service"];
|
partOf = ["tlsa-update.service"];
|
||||||
wantedBy = ["multi-user.target"];
|
wantedBy = ["multi-user.target"];
|
||||||
path = [pkgs.coreutils];
|
path = [pkgs.coreutils];
|
||||||
|
|||||||
@@ -33,6 +33,10 @@
|
|||||||
# users.
|
# users.
|
||||||
install -D -m 0644 "$SRC_CERT" "$DST_CERT"
|
install -D -m 0644 "$SRC_CERT" "$DST_CERT"
|
||||||
install -D -m 0640 "$SRC_KEY" "$DST_KEY"
|
install -D -m 0640 "$SRC_KEY" "$DST_KEY"
|
||||||
|
# Stalwart reads the key as user "stalwart" via %{file:...}%; regrant the
|
||||||
|
# group immediately so every sync leaves it readable (0640 root:stalwart)
|
||||||
|
# and webadmin config reload never fails with EACCES.
|
||||||
|
chgrp stalwart "$DST_KEY"
|
||||||
|
|
||||||
# 2) TLSA 3 1 1 = SHA-256 of the certificate's SubjectPublicKeyInfo (SPKI),
|
# 2) TLSA 3 1 1 = SHA-256 of the certificate's SubjectPublicKeyInfo (SPKI),
|
||||||
# NOT the whole certificate. Matching type 1 = SHA-256 of the SPKI DER.
|
# NOT the whole certificate. Matching type 1 = SHA-256 of the SPKI DER.
|
||||||
|
|||||||
Reference in New Issue
Block a user