2014-05-05 19:58:51 +01:00
|
|
|
{pkgs, config, lib, ...}:
|
2010-08-06 09:49:08 +01:00
|
|
|
|
|
|
|
let
|
|
|
|
|
2014-05-05 19:58:51 +01:00
|
|
|
inherit (lib) mkOption mkIf singleton;
|
2010-08-06 09:49:08 +01:00
|
|
|
|
|
|
|
inherit (pkgs) heimdal;
|
|
|
|
|
|
|
|
stateDir = "/var/heimdal";
|
|
|
|
in
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
###### interface
|
2011-09-14 19:20:50 +01:00
|
|
|
|
2010-08-06 09:49:08 +01:00
|
|
|
options = {
|
2011-09-14 19:20:50 +01:00
|
|
|
|
2010-08-06 09:49:08 +01:00
|
|
|
services.kerberos_server = {
|
|
|
|
|
|
|
|
enable = mkOption {
|
|
|
|
default = false;
|
|
|
|
description = ''
|
|
|
|
Enable the kerberos authentification server.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
###### implementation
|
|
|
|
|
|
|
|
config = mkIf config.services.kerberos_server.enable {
|
2011-09-14 19:20:50 +01:00
|
|
|
|
2010-08-06 09:49:08 +01:00
|
|
|
environment.systemPackages = [ heimdal ];
|
2011-09-14 19:20:50 +01:00
|
|
|
|
2010-08-06 09:49:08 +01:00
|
|
|
services.xinetd.enable = true;
|
2014-05-05 19:58:51 +01:00
|
|
|
services.xinetd.services = lib.singleton
|
2010-08-06 09:49:08 +01:00
|
|
|
{ name = "kerberos-adm";
|
|
|
|
flags = "REUSE NAMEINARGS";
|
|
|
|
protocol = "tcp";
|
|
|
|
user = "root";
|
2012-11-29 14:16:30 +00:00
|
|
|
server = "${pkgs.tcp_wrappers}/sbin/tcpd";
|
2010-08-06 09:49:08 +01:00
|
|
|
serverArgs = "${pkgs.heimdal}/sbin/kadmind";
|
|
|
|
};
|
|
|
|
|
|
|
|
jobs.kdc =
|
|
|
|
{ description = "Kerberos Domain Controller daemon";
|
|
|
|
|
|
|
|
startOn = "ip-up";
|
|
|
|
|
|
|
|
preStart =
|
|
|
|
''
|
|
|
|
mkdir -m 0755 -p ${stateDir}
|
|
|
|
'';
|
|
|
|
|
|
|
|
exec = "${heimdal}/sbin/kdc";
|
|
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
jobs.kpasswdd =
|
|
|
|
{ description = "Kerberos Domain Controller daemon";
|
|
|
|
|
|
|
|
startOn = "ip-up";
|
|
|
|
|
|
|
|
exec = "${heimdal}/sbin/kpasswdd";
|
|
|
|
};
|
|
|
|
};
|
2011-09-14 19:20:50 +01:00
|
|
|
|
2010-08-06 09:49:08 +01:00
|
|
|
}
|