summaryrefslogtreecommitdiffstats
path: root/krebs/2configs/acme.nix
diff options
context:
space:
mode:
authorlassulus <lassulus@lassul.us>2021-12-09 14:52:35 +0100
committerlassulus <lassulus@lassul.us>2021-12-09 14:52:35 +0100
commitabd82c4faf8a882c72f4f19125a280d8d14f852f (patch)
tree6bccc24c243c1e66c18d8a99f883bdd59b347ab8 /krebs/2configs/acme.nix
parentfba330ab36ed3f0c5f5b01a1c434ed9e8281846a (diff)
ca.r: serve ca.crt via nginx
Diffstat (limited to 'krebs/2configs/acme.nix')
-rw-r--r--krebs/2configs/acme.nix4
1 files changed, 3 insertions, 1 deletions
diff --git a/krebs/2configs/acme.nix b/krebs/2configs/acme.nix
index b5e51a1a2..056aa7ae4 100644
--- a/krebs/2configs/acme.nix
+++ b/krebs/2configs/acme.nix
@@ -7,15 +7,17 @@ in {
email = "spam@krebsco.de";
certs.${domain}.server = "https://${domain}:1443/acme/acme/directory"; # use 1443 here cause bootstrapping loop
};
+ networking.firewall.allowedTCPPorts = [ 80 443 ];
services.nginx = {
enable = true;
recommendedProxySettings = true;
virtualHosts.${domain} = {
- forceSSL = true;
+ addSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "https://localhost:1443";
};
+ locations."= /ca.crt".alias = ../6assets/krebsAcmeCA.crt;
};
};
krebs.secret.files.krebsAcme = {