HSMW-VPN Working

This commit is contained in:
nx2
2024-03-27 11:05:57 +01:00
parent 9953f8231b
commit 4e3b643d20
4 changed files with 82 additions and 14 deletions

View File

@@ -24,6 +24,8 @@
# '';
"ipsec.d/hsmw.secrets".text = ''${secrets.email.hsmw.mail} : EAP "${secrets.email.hsmw.password}"'';
"ipsec.d/USERTrust-ECC.pem".source = ../secrets/vpn-hsmw/USERTrust-ECC-Certification-Authority.pem;
"ipsec.d/USERTrust-RSA.pem".source = ../secrets/vpn-hsmw/USERTrust-RSA-Certification-Authority.pem;
};
services.strongswan = {
@@ -77,8 +79,11 @@
"resolve"
];
secrets = [ "/etc/ipsec.d/hsmw.secrets" ];
# ca = {
# ??? # https://mynixos.com/nixpkgs/option/services.strongswan.ca
# }
ca = {
hsmw = {
auto = "add";
cacert = "/etc/ipsec.d/USERTrust-RSA.pem";
};
};
};
}