X-Git-Url: https://git.immae.eu/?a=blobdiff_plain;f=nixops%2Fmodules%2Fwebsites%2Fdefault.nix;h=cd2b38aefecc95a4a7160bc329e8b45e08c179fe;hb=85f5ed68104de9edd8f8e532dc0c2de931e3ca1b;hp=ad97d7f8a0782db67b0f03e6f1a2efeac2dd84d3;hpb=e2ca51b2f47652f64b497e53249c29ad4b96a6e9;p=perso%2FImmae%2FConfig%2FNix.git diff --git a/nixops/modules/websites/default.nix b/nixops/modules/websites/default.nix index ad97d7f..cd2b38a 100644 --- a/nixops/modules/websites/default.nix +++ b/nixops/modules/websites/default.nix @@ -8,7 +8,7 @@ let enableSSL = true; sslServerCert = "/var/lib/acme/${vhostConf.certName}/cert.pem"; sslServerKey = "/var/lib/acme/${vhostConf.certName}/key.pem"; - sslServerChain = "/var/lib/acme/${vhostConf.certName}/fullchain.pem"; + sslServerChain = "/var/lib/acme/${vhostConf.certName}/chain.pem"; logFormat = "combinedVhost"; listen = map (ip: { inherit ip; port = 443; }) cfg.ips; hostName = builtins.head vhostConf.hosts; @@ -167,6 +167,7 @@ in }; config = { + users.users.wwwrun.extraGroups = [ "keys" ]; networking.firewall.allowedTCPPorts = [ 80 443 ]; nixpkgs.overlays = [ (self: super: rec { @@ -228,6 +229,24 @@ in services.myWebsites.TellesFlorian.integration.enable = true; services.myWebsites.Florian.integration.enable = true; + deployment.keys.apache-ldap = { + user = "wwwrun"; + group = "wwwrun"; + permissions = "0400"; + text = '' + + + AuthLDAPURL ldap://ldap.immae.eu:389/dc=immae,dc=eu STARTTLS + AuthLDAPBindDN cn=httpd,ou=services,dc=immae,dc=eu + AuthLDAPBindPassword "${myconfig.env.httpd.ldap.password}" + AuthType Basic + AuthName "Authentification requise (Acces LDAP)" + AuthBasicProvider ldap + + + ''; + }; + services.myWebsites.apacheConfig = { gzip = { modules = [ "deflate" "filter" ]; @@ -265,16 +284,7 @@ in LDAPOpCacheTTL 600 - - - AuthLDAPURL ldap://ldap.immae.eu:389/dc=immae,dc=eu STARTTLS - AuthLDAPBindDN cn=httpd,ou=services,dc=immae,dc=eu - AuthLDAPBindPassword "${myconfig.env.httpd.ldap.password}" - AuthType Basic - AuthName "Authentification requise (Acces LDAP)" - AuthBasicProvider ldap - - + Include /run/keys/apache-ldap ''; }; global = { @@ -415,8 +425,10 @@ in phpOptions = '' session.save_path = "/var/lib/php/sessions" post_max_size = 20M - session.gc_maxlifetime = 60*60*24*15 - session.cache_expire = 60*24*30 + ; 15 days (seconds) + session.gc_maxlifetime = 1296000 + ; 30 days (minutes) + session.cache_expire = 43200 ''; extraConfig = '' log_level = notice