mirror of https://gitlab.crans.org/nounous/nixos
99 lines
2.1 KiB
Nix
99 lines
2.1 KiB
Nix
{
|
|
config,
|
|
lib,
|
|
self,
|
|
...
|
|
}:
|
|
|
|
let
|
|
cfg = config.crans.users;
|
|
|
|
inherit (lib)
|
|
mkEnableOption
|
|
mkOption
|
|
types
|
|
;
|
|
in
|
|
|
|
{
|
|
options.crans.users = {
|
|
ldap = {
|
|
enable = mkEnableOption "Authentification par le LDAP adm.";
|
|
};
|
|
|
|
root = {
|
|
passwordFile = mkOption {
|
|
type = types.externalPath;
|
|
default = ../../secrets/common/root.age;
|
|
example = ../../secrets/apprentix/root.age;
|
|
description = "Fichier chiffré par age contenant le mot de passe root.";
|
|
};
|
|
};
|
|
};
|
|
|
|
config = {
|
|
age.secrets.root-passwd-hash = {
|
|
file = cfg.root.passwordFile;
|
|
};
|
|
|
|
users = {
|
|
mutableUsers = false;
|
|
|
|
motd =
|
|
let
|
|
shortRev = self.shortRev or self.dirtyShortRev or "inconnue";
|
|
rev = self.rev or (lib.strings.removeSuffix "-dirty" (self.dirtyRev or "inconnue"));
|
|
isDirty = !(self ? rev);
|
|
in
|
|
''
|
|
${
|
|
if isDirty then "!! DIRTY !! " else ""
|
|
}Version déployée ${shortRev}, modifiée le ${self.lastModifiedDate or "??"}.
|
|
|
|
https://gitlab.crans.org/nounous/nixos/-/commit/${rev}
|
|
'';
|
|
|
|
users.root = {
|
|
hashedPasswordFile = config.age.secrets.root-passwd-hash.path;
|
|
};
|
|
|
|
ldap = {
|
|
enable = cfg.ldap.enable;
|
|
base = "dc=crans,dc=org";
|
|
server = "ldaps://ldap-adm.adm.crans.org/";
|
|
daemon = {
|
|
enable = true;
|
|
extraConfig = ''
|
|
ldap_version 3
|
|
tls_reqcert allow
|
|
map passwd loginShell /run/current-system/sw/bin/bash
|
|
'';
|
|
};
|
|
};
|
|
};
|
|
|
|
security.sudo = {
|
|
enable = true;
|
|
extraConfig = ''
|
|
# envoyer un email apres un fail de l'authentification
|
|
Defaults mail_badpass
|
|
|
|
# custom prompt
|
|
Defaults passprompt_override
|
|
Defaults passprompt="[sudo] mot de passe pour %p sur %h: "
|
|
'';
|
|
extraRules = [
|
|
{
|
|
groups = [ "_user" ];
|
|
runAs = "root:ALL";
|
|
commands = [ "NOPASSWD:/usr/bin/qm list" ];
|
|
}
|
|
{
|
|
groups = [ "_nounou" ];
|
|
commands = [ "ALL" ];
|
|
}
|
|
];
|
|
};
|
|
};
|
|
}
|