nixos/wireless: allow PKCS11 token access in the hardened service

This commit is contained in:
Nikita Rudenko
2026-08-09 03:08:54 +03:00
parent 3c1563438b
commit 2dca23ab8a
3 changed files with 44 additions and 7 deletions

View File

@@ -214,8 +214,15 @@ Certificates and other files supplied here need to be readable by the
`wpa_supplicant` user; it is therefore recommended to store them in the
`/etc/wpa_supplicant` directory.
If your network authentication protocol requires write access to files, smart
cards or TPM devices, you may have to disable security hardening with
With [](#opt-networking.wireless.pkcs11.enable), the default tpm2-pkcs11
database directory `/etc/tpm2_pkcs11` is available inside the sandbox. A
database in another location must be added explicitly:
```nix
{ systemd.services.wpa_supplicant.serviceConfig.BindPaths = [ "/var/lib/tpm2_pkcs11" ]; }
```
If your network authentication protocol requires other access that cannot be
granted explicitly, you may have to disable security hardening with
```nix
{ networking.wireless.enableHardening = false; }
```

View File

@@ -290,6 +290,13 @@ in
'';
};
# Give rw access for tss group to tpm2-pkcs11's system-wide token store.
# Consumers like tpm2-pkcs11 refuses to use a store they cannot lock and update.
systemd.tmpfiles.rules = lib.mkIf (cfg.pkcs11.enable && cfg.tssGroup != null) [
"d /etc/tpm2_pkcs11 2770 root ${cfg.tssGroup} -"
"Z /etc/tpm2_pkcs11 ~2770 - ${cfg.tssGroup} -"
];
services.udev.extraRules = lib.mkIf cfg.applyUdevRules (udevRules cfg.tssUser cfg.tssGroup);
# Create the tss user and group only if the default value is used

View File

@@ -170,14 +170,27 @@ let
"/dev/rfkill"
]
++ lib.optional cfg.dbusControlled "/run/dbus"
++ lib.optional cfg.allowAuxiliaryImperativeNetworks "/etc/wpa_supplicant";
++ lib.optional cfg.allowAuxiliaryImperativeNetworks "/etc/wpa_supplicant"
# token access for the PKCS#11 backends
++ lib.optionals cfg.pkcs11.enable [
"-${config.security.tpm2.tctiEnvironment.deviceConf}"
"-/run/pcscd"
"-/etc/tpm2_pkcs11"
];
BindReadOnlyPaths = [
builtins.storeDir
"/etc/"
]
++ cfg.extraConfigFiles
++ lib.optional (cfg.secretsFile != null) cfg.secretsFile;
DeviceAllow = "/dev/rfkill rw";
DeviceAllow = [
"/dev/rfkill rw"
]
++ lib.optional cfg.pkcs11.enable "${config.security.tpm2.tctiEnvironment.deviceConf} rw";
# Grant tss group for tpm2 access if pkcs11 is enabled.
SupplementaryGroups = lib.optional (
cfg.pkcs11.enable && config.security.tpm2.enable && config.security.tpm2.tssGroup != null
) config.security.tpm2.tssGroup;
LockPersonality = true;
MemoryDenyWriteExecute = true;
NoNewPrivileges = true;
@@ -643,9 +656,19 @@ in
PKCS#11 tokens such as smartcards or a TPM.
::: {.note}
Hardware-backed tokens usually also require disabling
{option}`networking.wireless.enableHardening`, since the hardened
service cannot access device nodes such as the TPM.
With {option}`networking.wireless.enableHardening` enabled,
the service is additionally granted:
- Membership in {option}`security.tpm2.tssGroup`.
- Access to the TPM device configured by
{option}`security.tpm2.tctiEnvironment.deviceConf`.
- pcscd socket for smartcard readers.
- Access to default system-wide token store `/etc/tpm2_pkcs11`.
Note that the hardened service by default has no home directory,
so only the system store location applies.
The store must be writable by {option}`security.tpm2.tssGroup`.
Enable {option}`security.tpm2.pkcs11.enable` option to grant
tss group access to the store.
:::
::: {.note}