diff options
-rw-r--r-- | nixos/doc/manual/release-notes/rl-2009.xml | 4 | ||||
-rw-r--r-- | nixos/modules/security/duosec.nix | 5 |
2 files changed, 7 insertions, 2 deletions
diff --git a/nixos/doc/manual/release-notes/rl-2009.xml b/nixos/doc/manual/release-notes/rl-2009.xml index 1ca172c99f131..a9a6003d1e8a0 100644 --- a/nixos/doc/manual/release-notes/rl-2009.xml +++ b/nixos/doc/manual/release-notes/rl-2009.xml @@ -103,6 +103,10 @@ <link linkend="opt-security.duosec.secretKeyFile">security.duosec.secretKeyFile</link> option for better security. </para> + <para> + <literal>security.duosec.ikey</literal> has been renamed to + <link linkend="opt-security.duosec.integrationKey">security.duosec.integrationKey</link>. + </para> </listitem> </itemizedlist> </section> diff --git a/nixos/modules/security/duosec.nix b/nixos/modules/security/duosec.nix index 38169706463dd..71428b82f5dac 100644 --- a/nixos/modules/security/duosec.nix +++ b/nixos/modules/security/duosec.nix @@ -9,7 +9,7 @@ let configFilePam = '' [duo] - ikey=${cfg.ikey} + ikey=${cfg.integrationKey} host=${cfg.host} ${optionalString (cfg.groups != "") ("groups="+cfg.groups)} failmode=${cfg.failmode} @@ -27,6 +27,7 @@ in { imports = [ (mkRenamedOptionModule [ "security" "duosec" "group" ] [ "security" "duosec" "groups" ]) + (mkRenamedOptionModule [ "security" "duosec" "ikey" ] [ "security" "duosec" "integrationKey" ]) (mkRemovedOptionModule [ "security" "duosec" "skey" ] "The insecure security.duosec.skey option has been replaced by a new security.duosec.secretKeyFile option. Use this new option to store a secure copy of your key instead.") ]; @@ -44,7 +45,7 @@ in description = "If enabled, protect logins with Duo Security using PAM support."; }; - ikey = mkOption { + integrationKey = mkOption { type = types.str; description = "Integration key."; }; |