summaryrefslogtreecommitdiffstats
path: root/nixos/modules/services/networking/freeradius.nix
blob: 081085d884bdbcbc8bb4f031948cdde036e345fc (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
{
  config,
  lib,
  pkgs,
  ...
}:
let

  cfg = config.services.freeradius;

  freeradiusService = cfg: {
    description = "FreeRadius server";
    wantedBy = [ "multi-user.target" ];
    after = [ "network.target" ];
    wants = [ "network.target" ];
    preStart = ''
      ${cfg.package}/bin/radiusd -C -d ${cfg.configDir} -l stdout
    '';

    serviceConfig = {
      ExecStart =
        "${cfg.package}/bin/radiusd -f -d ${cfg.configDir} -l stdout" + lib.optionalString cfg.debug " -xx";
      ExecReload = [
        "${cfg.package}/bin/radiusd -C -d ${cfg.configDir} -l stdout"
        "${pkgs.coreutils}/bin/kill -HUP $MAINPID"
      ];
      User = "radius";
      ProtectSystem = "full";
      ProtectHome = "on";
      Restart = "on-failure";
      RestartSec = 1;
      LogsDirectory = "radius";
    };
  };

  freeradiusConfig = {
    enable = lib.mkEnableOption "the freeradius server";

    package = lib.mkPackageOption pkgs "freeradius" { };

    configDir = lib.mkOption {
      type = lib.types.path;
      default = "/etc/raddb";
      description = ''
        The path of the freeradius server configuration directory.
      '';
    };

    debug = lib.mkOption {
      type = lib.types.bool;
      default = false;
      description = ''
        Whether to enable debug logging for freeradius (-xx
        option). This should not be left on, since it includes
        sensitive data such as passwords in the logs.
      '';
    };

  };

in

{

  ###### interface

  options = {
    services.freeradius = freeradiusConfig;
  };

  ###### implementation

  config = lib.mkIf (cfg.enable) {

    users = {
      users.radius = {
        # uid = config.ids.uids.radius;
        description = "Radius daemon user";
        isSystemUser = true;
        group = "radius";
      };
      groups.radius = { };
    };

    systemd.services.freeradius = freeradiusService cfg;
    warnings = lib.optional cfg.debug "Freeradius debug logging is enabled. This will log passwords in plaintext to the journal!";

  };

}