nixos/nginx: allow using security.dhparams via sslDhparam = true
Currently `security.dhparams` is only used by `services.dovecot2` : https://github.com/NixOS/nixpkgs/blob/98ff3f9af2684f6136c24beef08f5e2033fc5389/nixos/modules/services/mail/dovecot.nix#L627-L630 Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
This commit is contained in:
@@ -202,7 +202,11 @@ let
|
||||
|
||||
ssl_protocols ${cfg.sslProtocols};
|
||||
${optionalString (cfg.sslCiphers != null) "ssl_ciphers ${cfg.sslCiphers};"}
|
||||
${optionalString (cfg.sslDhparam != null) "ssl_dhparam ${cfg.sslDhparam};"}
|
||||
${optionalString (cfg.sslDhparam != false)
|
||||
"ssl_dhparam ${
|
||||
if cfg.sslDhparam == true then config.security.dhparams.params.nginx.path else cfg.sslDhparam
|
||||
};"
|
||||
}
|
||||
|
||||
${optionalString cfg.recommendedTlsSettings ''
|
||||
# Keep in sync with https://ssl-config.mozilla.org/#server=nginx&config=intermediate
|
||||
@@ -982,10 +986,10 @@ in
|
||||
};
|
||||
|
||||
sslDhparam = mkOption {
|
||||
type = types.nullOr types.path;
|
||||
default = null;
|
||||
type = types.either types.path types.bool;
|
||||
default = false;
|
||||
example = "/path/to/dhparams.pem";
|
||||
description = "Path to DH parameters file.";
|
||||
description = "Path to DH parameters file, or `true` to generate with `security.dhparms.params.nginx`.";
|
||||
};
|
||||
|
||||
proxyResolveWhileRunning = mkOption {
|
||||
@@ -1652,6 +1656,8 @@ in
|
||||
in
|
||||
listToAttrs acmePairs;
|
||||
|
||||
security.dhparams.params.nginx = lib.mkIf (cfg.sslDhparam == true) { };
|
||||
|
||||
users.users = optionalAttrs (cfg.user == "nginx") {
|
||||
nginx = {
|
||||
group = cfg.group;
|
||||
|
||||
Reference in New Issue
Block a user