diff options
Diffstat (limited to 'hosts/surtr/email/default.nix')
-rw-r--r-- | hosts/surtr/email/default.nix | 6 |
1 files changed, 5 insertions, 1 deletions
diff --git a/hosts/surtr/email/default.nix b/hosts/surtr/email/default.nix index 9c56fb93..52955cd2 100644 --- a/hosts/surtr/email/default.nix +++ b/hosts/surtr/email/default.nix | |||
@@ -167,7 +167,11 @@ with lib; | |||
167 | 167 | ||
168 | systemd.services.postfix = { | 168 | systemd.services.postfix = { |
169 | preStart = concatMapStringsSep "\n" (domain: '' | 169 | preStart = concatMapStringsSep "\n" (domain: '' |
170 | cat /var/lib/acme/${domain}/key.pem /var/lib/acme/${domain}/full.pem > /var/lib/acme/${domain}/sni.pem | 170 | ( |
171 | umask 0037 | ||
172 | cat /var/lib/acme/${domain}/key.pem /var/lib/acme/${domain}/full.pem > /var/lib/acme/${domain}/sni.pem | ||
173 | chown acme:acme /var/lib/acme/${domain}/sni.pem | ||
174 | ) | ||
171 | '') ["bouncy.email" "mailin.bouncy.email" "mailsub.bouncy.email" "surtr.yggdrasil.li"]; | 175 | '') ["bouncy.email" "mailin.bouncy.email" "mailsub.bouncy.email" "surtr.yggdrasil.li"]; |
172 | 176 | ||
173 | serviceConfig.LoadCredential = [ | 177 | serviceConfig.LoadCredential = [ |