summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGregor Kleen <gkleen@yggdrasil.li>2020-08-16 14:25:49 +0200
committerGregor Kleen <gkleen@yggdrasil.li>2020-08-16 14:25:49 +0200
commitff6d6d3b3ede0001cf4c3d8259703a41749166be (patch)
tree2aeee15315a2e34af477c7b005382126fe07572c
parent626e1d6d8bd4bde5d629e2f925969a3593dcc9ac (diff)
downloadnixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.tar
nixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.tar.gz
nixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.tar.bz2
nixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.tar.xz
nixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.zip
ymir: fix postfix dane
-rw-r--r--ymir.nix2
1 files changed, 1 insertions, 1 deletions
diff --git a/ymir.nix b/ymir.nix
index 934c2374..4adaf128 100644
--- a/ymir.nix
+++ b/ymir.nix
@@ -444,6 +444,7 @@ in rec {
444 ''}'']; 444 ''}''];
445 sslCert = "/var/lib/acme/yggdrasil.li/fullchain.pem"; 445 sslCert = "/var/lib/acme/yggdrasil.li/fullchain.pem";
446 sslKey = "/var/lib/acme/yggdrasil.li/key.pem"; 446 sslKey = "/var/lib/acme/yggdrasil.li/key.pem";
447 useDANE = true;
447 config = { 448 config = {
448 #the dh params 449 #the dh params
449 smtpd_tls_dh1024_param_file = config.security.dhparams.params."postfix-1024".path; 450 smtpd_tls_dh1024_param_file = config.security.dhparams.params."postfix-1024".path;
@@ -469,7 +470,6 @@ in rec {
469 smtp_tls_loglevel = "1"; 470 smtp_tls_loglevel = "1";
470 471
471 smtp_dns_support_level = "dnssec"; 472 smtp_dns_support_level = "dnssec";
472 smtp_tls_security_level = "dane";
473 473
474 transport_maps = ''regexp:${pkgs.writeText "transport" '' 474 transport_maps = ''regexp:${pkgs.writeText "transport" ''
475 /@(rpgs?|lists?|l)\.(.*\.)?(yggdrasil\.li|praseodym\.org|141\.li|xmpp\.li|kleen\.li|dirty-haskell\.org|nights\.email|yggdrasil|localdomain|localhost|ymir)$/ mlmmj: 475 /@(rpgs?|lists?|l)\.(.*\.)?(yggdrasil\.li|praseodym\.org|141\.li|xmpp\.li|kleen\.li|dirty-haskell\.org|nights\.email|yggdrasil|localdomain|localhost|ymir)$/ mlmmj: