summary refs log tree commit diff
path: root/nixos/modules/security
AgeCommit message (Expand)AuthorFilesLines
2023-09-22nixos/sudo-rs: add crossCompile 'fix'Maciej Krüger1-1/+1
2023-09-22nixos/sudo-rs: initMaciej Krüger1-9/+9
2023-09-22nixos/sudo: revert sudo-rs 922926cfbc08f3e4065b51a41ebf613e59888015 (partial ...Maciej Krüger2-98/+367
2023-09-18nixos/sudo: Add myself as maintainernicoo1-0/+2
2023-09-18nixos/sudo: Generate `sudo-i` PAM config for interactive use of `sudo-rs`nicoo1-1/+4
2023-09-18nixos/sudo: Only wrap `sudoedit` when using Miller's sudonicoo1-1/+2
2023-09-18nixos/{sudo, terminfo}: Adjust defaults for compatibility with `sudo-rs`nicoo1-6/+4
2023-09-18nixos/sudo: Check syntax using the configured packagenicoo1-3/+1
2023-09-18nixos/sudo: Drop the sudoers comment for `extraRules`nicoo1-13/+10
2023-09-18nixos/sudo: Make the default rules' options configurablenicoo1-2/+11
2023-09-18nixos/sudo: Handle `root`'s default rule through `extraRules`nicoo1-11/+21
2023-09-18nixos/sudo: Drop useless `lib.` qualifiersnicoo1-26/+23
2023-09-18nixos/sudo: Refactor checks for Todd C. Miller's implemetationnicoo1-3/+5
2023-09-18nixos/sudo: Refactor option definitionsnicoo1-8/+8
2023-09-18nixos/sudo: Only keep SSH_AUTH_SOCK if used for authenticationnicoo1-2/+6
2023-09-18nixos/sudo: Don't include empty sectionsnicoo1-6/+6
2023-09-18nixos/sudo: Split up `configFile` into individual sectionsnicoo1-6/+12
2023-09-11nixos/acme: rename option credentialsFile to environmentFiledatafoo2-6/+10
2023-09-11nixos/acme: add option to set credential filesdatafoo1-0/+31
2023-09-11nixos/pam: fix typo in fscrypt enable optionmib1-1/+1
2023-09-10Merge pull request #251770 from robryk/suidwrapapparmPierre Bourdon3-114/+19
2023-09-09security/acme: limit concurrent certificate generationsOliver Schmidt1-13/+93
2023-09-04nixos/sudo: Guard against `security.sudo.package = pkgs.sudo-rs;`nicoo1-0/+4
2023-08-27nixos/security/wrappers: remove all the assertions about readlink(/proc/self/...Robert Obryk3-84/+2
2023-08-27nixos/security/wrappers: read capabilities off /proc/self/exe directlyRobert Obryk1-1/+1
2023-08-27nixos/security/wrappers: stop using `.real` filesRobert Obryk3-32/+16
2023-08-27nixos/security/wrappers: generate a separate and more complete apparmor polic...Robert Obryk1-3/+6
2023-08-24Revert "nixos/security/wrappers: simplifications and a fix for #98863"Pierre Bourdon3-13/+110
2023-08-16nixos/security/wrappers: remove all the assertions about readlink(/proc/self/...Robert Obryk3-84/+2
2023-08-16nixos/security/wrappers: read capabilities off /proc/self/exe directlyRobert Obryk1-1/+1
2023-08-16nixos/security/wrappers: stop using `.real` filesRobert Obryk3-30/+15
2023-08-10security/pam: add umask option to configure pam_mkhomedirAaron Andersen1-1/+11
2023-08-10Merge pull request #231673 from symphorien/suid_wrappers_usernsRyan Lahfa1-6/+34
2023-08-09nixos/wrappers: allow setuid and setgid wrappers to run in user namespacesGuillaume Girol1-6/+34
2023-08-08treewide: stop using types.stringLin Jian2-2/+2
2023-08-04Merge pull request #242538 from tnias/fix/apparmorajs1241-2/+7
2023-07-12nixos/apparmor: support custom i18n glibc localesPhilipp Bartsch1-1/+1
2023-07-09nixos/apparmor: fix syntax in abstractions/bashPhilipp Bartsch1-1/+1
2023-07-09nixos/apparmor: add missing abstraction/nss-systemdPhilipp Bartsch1-0/+3
2023-07-09pam_dp9ik: init at 1.5Jacob Moody1-0/+29
2023-07-08nixos/apparmor: make abstractions/ssl_certs more go friendlyPhilipp Bartsch1-0/+2
2023-07-06nixos/qemu-vm: use CA certificates from hostMichael Hoang1-1/+5
2023-06-25treewide: use optional instead of 'then []'Felix Buehler2-8/+7
2023-06-11nixos/pam: support KanidmMax1-0/+16
2023-05-25nixos/pam_mount: fix mounts without options (#234026)Jenny1-2/+4
2023-05-20nixos/pam_mount: fix cryptmount options (#232873)Jenny1-1/+13
2023-05-15Merge pull request #231316 from hercules-ci/nixos-system.checksRobert Hensing1-1/+1
2023-05-15Merge pull request #231954 from mac-chaffee/acme-ipv6Nick Cao1-1/+1
2023-05-15nixos/pam: fix ZFS support assertionRaito Bezarius1-1/+1
2023-05-15nixos/pam: assert ZFS support for PAM moduleNicola Squartini1-0/+6