2018-01-27 14:44:50 +00:00
|
|
|
{ config, lib, pkgs, ... }:
|
|
|
|
|
|
|
|
with lib;
|
|
|
|
|
|
|
|
let
|
|
|
|
|
|
|
|
cfg = config.services.freeradius;
|
|
|
|
|
|
|
|
freeradiusService = cfg:
|
|
|
|
{
|
|
|
|
description = "FreeRadius server";
|
|
|
|
wantedBy = ["multi-user.target"];
|
2020-02-27 17:25:43 +00:00
|
|
|
after = ["network.target"];
|
|
|
|
wants = ["network.target"];
|
2018-01-27 14:44:50 +00:00
|
|
|
preStart = ''
|
|
|
|
${pkgs.freeradius}/bin/radiusd -C -d ${cfg.configDir} -l stdout
|
|
|
|
'';
|
|
|
|
|
|
|
|
serviceConfig = {
|
2020-03-02 14:39:14 +00:00
|
|
|
ExecStart = "${pkgs.freeradius}/bin/radiusd -f -d ${cfg.configDir} -l stdout" +
|
|
|
|
optionalString cfg.debug " -xx";
|
2018-01-27 14:44:50 +00:00
|
|
|
ExecReload = [
|
|
|
|
"${pkgs.freeradius}/bin/radiusd -C -d ${cfg.configDir} -l stdout"
|
|
|
|
"${pkgs.coreutils}/bin/kill -HUP $MAINPID"
|
|
|
|
];
|
|
|
|
User = "radius";
|
|
|
|
ProtectSystem = "full";
|
|
|
|
ProtectHome = "on";
|
|
|
|
Restart = "on-failure";
|
|
|
|
RestartSec = 2;
|
2021-12-07 07:51:57 +00:00
|
|
|
LogsDirectory = "radius";
|
2018-01-27 14:44:50 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
freeradiusConfig = {
|
|
|
|
enable = mkEnableOption "the freeradius server";
|
|
|
|
|
|
|
|
configDir = mkOption {
|
|
|
|
type = types.path;
|
|
|
|
default = "/etc/raddb";
|
2022-07-28 21:19:15 +00:00
|
|
|
description = lib.mdDoc ''
|
2018-01-27 14:44:50 +00:00
|
|
|
The path of the freeradius server configuration directory.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2020-03-02 14:39:14 +00:00
|
|
|
debug = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = false;
|
2022-07-28 21:19:15 +00:00
|
|
|
description = lib.mdDoc ''
|
2020-03-02 14:39:14 +00:00
|
|
|
Whether to enable debug logging for freeradius (-xx
|
|
|
|
option). This should not be left on, since it includes
|
|
|
|
sensitive data such as passwords in the logs.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2018-01-27 14:44:50 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
in
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
###### interface
|
|
|
|
|
|
|
|
options = {
|
|
|
|
services.freeradius = freeradiusConfig;
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
###### implementation
|
|
|
|
|
|
|
|
config = mkIf (cfg.enable) {
|
|
|
|
|
|
|
|
users = {
|
2018-06-29 23:58:35 +00:00
|
|
|
users.radius = {
|
2018-01-27 14:44:50 +00:00
|
|
|
/*uid = config.ids.uids.radius;*/
|
|
|
|
description = "Radius daemon user";
|
2021-12-07 07:51:57 +00:00
|
|
|
isSystemUser = true;
|
2018-01-27 14:44:50 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
systemd.services.freeradius = freeradiusService cfg;
|
2020-03-02 14:39:14 +00:00
|
|
|
warnings = optional cfg.debug "Freeradius debug logging is enabled. This will log passwords in plaintext to the journal!";
|
2018-01-27 14:44:50 +00:00
|
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
}
|