modules/enterprise: remove kerberos config
This commit is contained in:
parent
640eb9df23
commit
e34287cd05
1 changed files with 0 additions and 23 deletions
|
@ -1,31 +1,8 @@
|
|||
{ config, depot, lib, tools, ... }:
|
||||
let
|
||||
orgDomain = tools.meta.domain;
|
||||
orgRealm = lib.toUpper orgDomain;
|
||||
host = depot.reflection;
|
||||
in {
|
||||
krb5 = {
|
||||
enable = true;
|
||||
domain_realm = {
|
||||
${orgDomain} = orgRealm;
|
||||
".${orgDomain}" = orgRealm;
|
||||
};
|
||||
libdefaults = {
|
||||
default_realm = orgRealm;
|
||||
dns_lookup_kdc = true;
|
||||
rdns = false;
|
||||
forwardable = true;
|
||||
default_ccache_name = "KEYRING:persistent:%{uid}";
|
||||
};
|
||||
realms = {
|
||||
"${orgRealm}" = rec {
|
||||
inherit (tools.identity.kerberos) kdc;
|
||||
admin_server = kdc;
|
||||
kpasswd_server = kdc;
|
||||
default_domain = orgDomain;
|
||||
};
|
||||
};
|
||||
};
|
||||
networking.domain = lib.mkDefault "${host.enterprise.subdomain or "services"}.${orgDomain}";
|
||||
networking.search = [ config.networking.domain "search.${orgDomain}" ];
|
||||
security.pki.certificates = [ (builtins.readFile ../../data/ca.crt) ];
|
||||
|
|
Loading…
Reference in a new issue