diff --git a/nixos/doc/manual/configuration/wireless.section.md b/nixos/doc/manual/configuration/wireless.section.md index dda26028031c..9cca6d10bbc6 100644 --- a/nixos/doc/manual/configuration/wireless.section.md +++ b/nixos/doc/manual/configuration/wireless.section.md @@ -214,8 +214,15 @@ Certificates and other files supplied here need to be readable by the `wpa_supplicant` user; it is therefore recommended to store them in the `/etc/wpa_supplicant` directory. -If your network authentication protocol requires write access to files, smart -cards or TPM devices, you may have to disable security hardening with +With [](#opt-networking.wireless.pkcs11.enable), the default tpm2-pkcs11 +database directory `/etc/tpm2_pkcs11` is available inside the sandbox. A +database in another location must be added explicitly: +```nix +{ systemd.services.wpa_supplicant.serviceConfig.BindPaths = [ "/var/lib/tpm2_pkcs11" ]; } +``` + +If your network authentication protocol requires other access that cannot be +granted explicitly, you may have to disable security hardening with ```nix { networking.wireless.enableHardening = false; } ``` diff --git a/nixos/modules/security/tpm2.nix b/nixos/modules/security/tpm2.nix index 91344069edf4..9c9c857fa820 100644 --- a/nixos/modules/security/tpm2.nix +++ b/nixos/modules/security/tpm2.nix @@ -290,6 +290,13 @@ in ''; }; + # Give rw access for tss group to tpm2-pkcs11's system-wide token store. + # Consumers like tpm2-pkcs11 refuses to use a store they cannot lock and update. + systemd.tmpfiles.rules = lib.mkIf (cfg.pkcs11.enable && cfg.tssGroup != null) [ + "d /etc/tpm2_pkcs11 2770 root ${cfg.tssGroup} -" + "Z /etc/tpm2_pkcs11 ~2770 - ${cfg.tssGroup} -" + ]; + services.udev.extraRules = lib.mkIf cfg.applyUdevRules (udevRules cfg.tssUser cfg.tssGroup); # Create the tss user and group only if the default value is used diff --git a/nixos/modules/services/networking/wpa_supplicant.nix b/nixos/modules/services/networking/wpa_supplicant.nix index 7cfbb543be40..9f6e0af18515 100644 --- a/nixos/modules/services/networking/wpa_supplicant.nix +++ b/nixos/modules/services/networking/wpa_supplicant.nix @@ -170,14 +170,27 @@ let "/dev/rfkill" ] ++ lib.optional cfg.dbusControlled "/run/dbus" - ++ lib.optional cfg.allowAuxiliaryImperativeNetworks "/etc/wpa_supplicant"; + ++ lib.optional cfg.allowAuxiliaryImperativeNetworks "/etc/wpa_supplicant" + # token access for the PKCS#11 backends + ++ lib.optionals cfg.pkcs11.enable [ + "-${config.security.tpm2.tctiEnvironment.deviceConf}" + "-/run/pcscd" + "-/etc/tpm2_pkcs11" + ]; BindReadOnlyPaths = [ builtins.storeDir "/etc/" ] ++ cfg.extraConfigFiles ++ lib.optional (cfg.secretsFile != null) cfg.secretsFile; - DeviceAllow = "/dev/rfkill rw"; + DeviceAllow = [ + "/dev/rfkill rw" + ] + ++ lib.optional cfg.pkcs11.enable "${config.security.tpm2.tctiEnvironment.deviceConf} rw"; + # Grant tss group for tpm2 access if pkcs11 is enabled. + SupplementaryGroups = lib.optional ( + cfg.pkcs11.enable && config.security.tpm2.enable && config.security.tpm2.tssGroup != null + ) config.security.tpm2.tssGroup; LockPersonality = true; MemoryDenyWriteExecute = true; NoNewPrivileges = true; @@ -643,9 +656,19 @@ in PKCS#11 tokens such as smartcards or a TPM. ::: {.note} - Hardware-backed tokens usually also require disabling - {option}`networking.wireless.enableHardening`, since the hardened - service cannot access device nodes such as the TPM. + With {option}`networking.wireless.enableHardening` enabled, + the service is additionally granted: + - Membership in {option}`security.tpm2.tssGroup`. + - Access to the TPM device configured by + {option}`security.tpm2.tctiEnvironment.deviceConf`. + - pcscd socket for smartcard readers. + - Access to default system-wide token store `/etc/tpm2_pkcs11`. + Note that the hardened service by default has no home directory, + so only the system store location applies. + + The store must be writable by {option}`security.tpm2.tssGroup`. + Enable {option}`security.tpm2.pkcs11.enable` option to grant + tss group access to the store. ::: ::: {.note}