summary refs log tree commit diff
path: root/nixos/modules/security
AgeCommit message (Expand)AuthorFilesLines
2020-01-30nixos/duosec: fix configuration issue with "groups" optionAaron Andersen1-3/+13
2020-01-09nixos/pam: cleanup services (#76885)Jörg Thalheim1-3/+0
2020-01-06treewide: use attrs instead of list for types.loaOf optionsrnhmjoj5-26/+24
2020-01-03pam: remove unused ftp serviceJörg Thalheim1-1/+0
2020-01-03pam: remove cups serviceJörg Thalheim1-1/+0
2020-01-03screen: move pam service to moduleJörg Thalheim1-1/+0
2019-12-19nixos/acme: implement postRun using ExecStartPostBen Price1-2/+2
2019-12-10Merge pull request #75343 from worldofpeace/polkit-no-root-adminworldofpeace1-3/+2
2019-12-10nixos/treewide: Move rename.nix imports to their respective modulesSilvan Mosberger5-1/+19
2019-12-09nixos/polkit: remove root from adminIdentitiesworldofpeace1-3/+2
2019-11-13nixos/acme: Fix allowKeysForGroup not applying immediately (#72056)Silvan Mosberger1-0/+6
2019-11-03pam_mount: change order of lines in pam_mount.confB YI1-3/+3
2019-10-30nixos/modules/security/acme.nix: add server optionFélix Baylac-Jacqué1-16/+30
2019-10-28nixos/acme: fix staging endpoint urlFranz Pletz1-1/+1
2019-10-27nixos/acme: Fix allowKeysForGroup not applying immediatelySilvan Mosberger1-0/+6
2019-10-23nixos/tests/letsencrypt: use Pebble instead of BoulderFélix Baylac-Jacqué1-0/+5
2019-10-23certbot: 0.31.0 -> 0.39.0Félix Baylac-Jacqué1-2/+2
2019-09-24Merge pull request #67748 from typetetris/yubico-local-authJörg Thalheim1-1/+18
2019-09-23nixos/systemd: pick more upstream tmpfiles confsFranz Pletz1-7/+0
2019-09-19Revert "nixos/doc: re-format"Eelco Dolstra2-10/+31
2019-09-18nixos/doc: re-formatJan Tojnar2-31/+10
2019-09-18nixos/system-environment: introduce environment.profileRelativeSessionVariablesRobert Helgesson1-1/+1
2019-09-02Merge branch 'master' into stagingVladimír Čunát3-7/+11
2019-08-31nixos/modules: Remove all usages of types.stringSilvan Mosberger2-7/+7
2019-08-31Merge pull request #62954 from abbradar/auditdAaron Andersen1-0/+4
2019-08-31Merge staging-next into stagingFrederik Rietdijk2-118/+37
2019-08-30yubico-pam: make local authentication possibleEric Wolf1-1/+18
2019-08-29Fix letsencrypt (#60219)Arian van Putten2-121/+37
2019-08-26treewide: remove redundant quotesvolth5-10/+10
2019-07-30nixos/hardened: make pti=on overridablePierre Bourdon1-0/+16
2019-07-19Renaming security.virtualization.flushL1DataCache to virtualisationMarek Mahut1-4/+4
2019-06-10auditd service: make more usefulNikolay Amiantov1-0/+4
2019-05-13FIx some malformed XML in option descriptionsEelco Dolstra1-16/+2
2019-05-12Merge pull request #61306 from joachifm/feat/fix-apparmor-boot-linux_5_1Joachim F1-0/+2
2019-05-11nixos/apparmor: ensure that apparmor is selected at bootJoachim Fasting1-0/+2
2019-05-07rngd: harden service config, from archWill Dietz1-0/+5
2019-05-06rngd: add option to run w/debug flagWill Dietz1-10/+23
2019-04-28nixos/apparmor: allow reloading profiles without losing confinementJoachim Fasting1-0/+3
2019-04-28nixos/apparmor: order before sysinit.targetJoachim Fasting1-1/+6
2019-04-21nixos/hardened: split description of allowUserNamespaces into parasJoachim Fasting1-7/+17
2019-04-14nixos/pam: Add GNOME keyring use_authtok directive to password groupAlexander Kahl1-0/+2
2019-03-31yubico-pam: add nixos integrationWill Dietz1-0/+60
2019-03-29Merge pull request #57519 (systemd-confinement)aszlig1-0/+199
2019-03-27nixos/confinement: Use PrivateMounts optionaszlig1-1/+1
2019-03-27nixos/confinement: Remove handling for StartOnlyaszlig1-7/+2
2019-03-17nixos/security: make duo support secure failure correctlyAlex Guzman1-1/+1
2019-03-15nixos/confinement: Explicitly set serviceConfigaszlig1-8/+20
2019-03-14nixos/confinement: Allow to include the full unitaszlig1-3/+24
2019-03-14nixos/confinement: Allow to configure /bin/shaszlig1-12/+23
2019-03-14nixos/systemd-chroot: Rename chroot to confinementaszlig1-13/+13