tv sendmail: setuid in exim-*

This commit is contained in:
tv 2016-02-27 13:10:21 +01:00
parent cc395214f5
commit 7cff3c0650
3 changed files with 8 additions and 6 deletions

View file

@ -177,12 +177,6 @@ with config.krebs.lib;
tv.iptables.input-internet-accept-new-tcp = singleton "ssh"; tv.iptables.input-internet-accept-new-tcp = singleton "ssh";
} }
{
# TODO: exim
security.setuidPrograms = [
"sendmail" # for sudo
];
}
{ {
environment.systemPackages = [ environment.systemPackages = [
pkgs.get pkgs.get

View file

@ -4,5 +4,9 @@ with config.krebs.lib;
{ {
krebs.exim-retiolum.enable = true; krebs.exim-retiolum.enable = true;
krebs.setuid.sendmail = {
filename = "${pkgs.exim}/bin/exim";
mode = "4111";
};
tv.iptables.input-retiolum-accept-new-tcp = singleton "smtp"; tv.iptables.input-retiolum-accept-new-tcp = singleton "smtp";
} }

View file

@ -40,5 +40,9 @@ with config.krebs.lib;
{ from = "mirko"; to = "mv"; } { from = "mirko"; to = "mv"; }
]; ];
}; };
krebs.setuid.sendmail = {
filename = "${pkgs.exim}/bin/exim";
mode = "4111";
};
tv.iptables.input-internet-accept-new-tcp = singleton "smtp"; tv.iptables.input-internet-accept-new-tcp = singleton "smtp";
} }