diff options
| author | Gregor Kleen <gkleen@yggdrasil.li> | 2020-08-16 14:25:49 +0200 |
|---|---|---|
| committer | Gregor Kleen <gkleen@yggdrasil.li> | 2020-08-16 14:25:49 +0200 |
| commit | ff6d6d3b3ede0001cf4c3d8259703a41749166be (patch) | |
| tree | 2aeee15315a2e34af477c7b005382126fe07572c | |
| parent | 626e1d6d8bd4bde5d629e2f925969a3593dcc9ac (diff) | |
| download | nixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.tar nixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.tar.gz nixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.tar.bz2 nixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.tar.xz nixos-ff6d6d3b3ede0001cf4c3d8259703a41749166be.zip | |
ymir: fix postfix dane
| -rw-r--r-- | ymir.nix | 2 |
1 files changed, 1 insertions, 1 deletions
| @@ -444,6 +444,7 @@ in rec { | |||
| 444 | ''}'']; | 444 | ''}'']; |
| 445 | sslCert = "/var/lib/acme/yggdrasil.li/fullchain.pem"; | 445 | sslCert = "/var/lib/acme/yggdrasil.li/fullchain.pem"; |
| 446 | sslKey = "/var/lib/acme/yggdrasil.li/key.pem"; | 446 | sslKey = "/var/lib/acme/yggdrasil.li/key.pem"; |
| 447 | useDANE = true; | ||
| 447 | config = { | 448 | config = { |
| 448 | #the dh params | 449 | #the dh params |
| 449 | smtpd_tls_dh1024_param_file = config.security.dhparams.params."postfix-1024".path; | 450 | smtpd_tls_dh1024_param_file = config.security.dhparams.params."postfix-1024".path; |
| @@ -469,7 +470,6 @@ in rec { | |||
| 469 | smtp_tls_loglevel = "1"; | 470 | smtp_tls_loglevel = "1"; |
| 470 | 471 | ||
| 471 | smtp_dns_support_level = "dnssec"; | 472 | smtp_dns_support_level = "dnssec"; |
| 472 | smtp_tls_security_level = "dane"; | ||
| 473 | 473 | ||
| 474 | transport_maps = ''regexp:${pkgs.writeText "transport" '' | 474 | transport_maps = ''regexp:${pkgs.writeText "transport" '' |
| 475 | /@(rpgs?|lists?|l)\.(.*\.)?(yggdrasil\.li|praseodym\.org|141\.li|xmpp\.li|kleen\.li|dirty-haskell\.org|nights\.email|yggdrasil|localdomain|localhost|ymir)$/ mlmmj: | 475 | /@(rpgs?|lists?|l)\.(.*\.)?(yggdrasil\.li|praseodym\.org|141\.li|xmpp\.li|kleen\.li|dirty-haskell\.org|nights\.email|yggdrasil|localdomain|localhost|ymir)$/ mlmmj: |
