mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-04 05:50:00 +00:00
nixos/wireless: allow PKCS11 token access in the hardened service
This commit is contained in:
@@ -214,8 +214,15 @@ Certificates and other files supplied here need to be readable by the
|
||||
`wpa_supplicant` user; it is therefore recommended to store them in the
|
||||
`/etc/wpa_supplicant` directory.
|
||||
|
||||
If your network authentication protocol requires write access to files, smart
|
||||
cards or TPM devices, you may have to disable security hardening with
|
||||
With [](#opt-networking.wireless.pkcs11.enable), the default tpm2-pkcs11
|
||||
database directory `/etc/tpm2_pkcs11` is available inside the sandbox. A
|
||||
database in another location must be added explicitly:
|
||||
```nix
|
||||
{ systemd.services.wpa_supplicant.serviceConfig.BindPaths = [ "/var/lib/tpm2_pkcs11" ]; }
|
||||
```
|
||||
|
||||
If your network authentication protocol requires other access that cannot be
|
||||
granted explicitly, you may have to disable security hardening with
|
||||
```nix
|
||||
{ networking.wireless.enableHardening = false; }
|
||||
```
|
||||
|
||||
@@ -290,6 +290,13 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
# Give rw access for tss group to tpm2-pkcs11's system-wide token store.
|
||||
# Consumers like tpm2-pkcs11 refuses to use a store they cannot lock and update.
|
||||
systemd.tmpfiles.rules = lib.mkIf (cfg.pkcs11.enable && cfg.tssGroup != null) [
|
||||
"d /etc/tpm2_pkcs11 2770 root ${cfg.tssGroup} -"
|
||||
"Z /etc/tpm2_pkcs11 ~2770 - ${cfg.tssGroup} -"
|
||||
];
|
||||
|
||||
services.udev.extraRules = lib.mkIf cfg.applyUdevRules (udevRules cfg.tssUser cfg.tssGroup);
|
||||
|
||||
# Create the tss user and group only if the default value is used
|
||||
|
||||
@@ -170,14 +170,27 @@ let
|
||||
"/dev/rfkill"
|
||||
]
|
||||
++ lib.optional cfg.dbusControlled "/run/dbus"
|
||||
++ lib.optional cfg.allowAuxiliaryImperativeNetworks "/etc/wpa_supplicant";
|
||||
++ lib.optional cfg.allowAuxiliaryImperativeNetworks "/etc/wpa_supplicant"
|
||||
# token access for the PKCS#11 backends
|
||||
++ lib.optionals cfg.pkcs11.enable [
|
||||
"-${config.security.tpm2.tctiEnvironment.deviceConf}"
|
||||
"-/run/pcscd"
|
||||
"-/etc/tpm2_pkcs11"
|
||||
];
|
||||
BindReadOnlyPaths = [
|
||||
builtins.storeDir
|
||||
"/etc/"
|
||||
]
|
||||
++ cfg.extraConfigFiles
|
||||
++ lib.optional (cfg.secretsFile != null) cfg.secretsFile;
|
||||
DeviceAllow = "/dev/rfkill rw";
|
||||
DeviceAllow = [
|
||||
"/dev/rfkill rw"
|
||||
]
|
||||
++ lib.optional cfg.pkcs11.enable "${config.security.tpm2.tctiEnvironment.deviceConf} rw";
|
||||
# Grant tss group for tpm2 access if pkcs11 is enabled.
|
||||
SupplementaryGroups = lib.optional (
|
||||
cfg.pkcs11.enable && config.security.tpm2.enable && config.security.tpm2.tssGroup != null
|
||||
) config.security.tpm2.tssGroup;
|
||||
LockPersonality = true;
|
||||
MemoryDenyWriteExecute = true;
|
||||
NoNewPrivileges = true;
|
||||
@@ -643,9 +656,19 @@ in
|
||||
PKCS#11 tokens such as smartcards or a TPM.
|
||||
|
||||
::: {.note}
|
||||
Hardware-backed tokens usually also require disabling
|
||||
{option}`networking.wireless.enableHardening`, since the hardened
|
||||
service cannot access device nodes such as the TPM.
|
||||
With {option}`networking.wireless.enableHardening` enabled,
|
||||
the service is additionally granted:
|
||||
- Membership in {option}`security.tpm2.tssGroup`.
|
||||
- Access to the TPM device configured by
|
||||
{option}`security.tpm2.tctiEnvironment.deviceConf`.
|
||||
- pcscd socket for smartcard readers.
|
||||
- Access to default system-wide token store `/etc/tpm2_pkcs11`.
|
||||
Note that the hardened service by default has no home directory,
|
||||
so only the system store location applies.
|
||||
|
||||
The store must be writable by {option}`security.tpm2.tssGroup`.
|
||||
Enable {option}`security.tpm2.pkcs11.enable` option to grant
|
||||
tss group access to the store.
|
||||
:::
|
||||
|
||||
::: {.note}
|
||||
|
||||
Reference in New Issue
Block a user