2014-05-05 19:58:51 +01:00
|
|
|
{pkgs, config, lib, ...}:
|
2010-08-06 09:49:08 +01:00
|
|
|
|
|
|
|
let
|
2018-07-20 20:36:12 +01:00
|
|
|
inherit (lib) mkOption mkIf;
|
2017-11-06 17:17:24 +00:00
|
|
|
cfg = config.services.kerberos_server;
|
2010-08-06 09:49:08 +01:00
|
|
|
stateDir = "/var/heimdal";
|
|
|
|
in
|
|
|
|
|
|
|
|
{
|
|
|
|
###### interface
|
|
|
|
options = {
|
|
|
|
services.kerberos_server = {
|
|
|
|
enable = mkOption {
|
|
|
|
default = false;
|
|
|
|
description = ''
|
|
|
|
Enable the kerberos authentification server.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
###### implementation
|
|
|
|
|
2017-11-06 17:17:24 +00:00
|
|
|
config = mkIf cfg.enable {
|
|
|
|
environment.systemPackages = [ pkgs.heimdalFull ];
|
2017-11-06 16:08:41 +00:00
|
|
|
systemd.services.kadmind = {
|
|
|
|
description = "Kerberos Administration Daemon";
|
|
|
|
script = "${pkgs.heimdalFull}/libexec/heimdal/kadmind";
|
|
|
|
};
|
2010-08-06 09:49:08 +01:00
|
|
|
|
2016-01-06 06:50:18 +00:00
|
|
|
systemd.services.kdc = {
|
2016-03-07 20:04:34 +00:00
|
|
|
description = "Key Distribution Center daemon";
|
2016-01-06 06:50:18 +00:00
|
|
|
wantedBy = [ "multi-user.target" ];
|
|
|
|
preStart = ''
|
|
|
|
mkdir -m 0755 -p ${stateDir}
|
|
|
|
'';
|
2017-11-06 17:17:24 +00:00
|
|
|
script = "${pkgs.heimdalFull}/libexec/heimdal/kdc";
|
2016-01-06 06:50:18 +00:00
|
|
|
};
|
2010-08-06 09:49:08 +01:00
|
|
|
|
2016-01-06 06:50:18 +00:00
|
|
|
systemd.services.kpasswdd = {
|
2016-03-07 20:04:34 +00:00
|
|
|
description = "Kerberos Password Changing daemon";
|
2016-01-06 06:50:18 +00:00
|
|
|
wantedBy = [ "multi-user.target" ];
|
2017-11-06 17:17:24 +00:00
|
|
|
script = "${pkgs.heimdalFull}/libexec/heimdal/kpasswdd";
|
2016-01-06 06:50:18 +00:00
|
|
|
};
|
2010-08-06 09:49:08 +01:00
|
|
|
};
|
|
|
|
}
|