2014-04-14 16:26:48 +02:00
|
|
|
|
{ config, lib, pkgs, ... }:
|
2014-02-18 10:38:35 +01:00
|
|
|
|
|
2014-04-14 16:26:48 +02:00
|
|
|
|
with lib;
|
2014-02-18 10:38:35 +01:00
|
|
|
|
|
|
|
|
|
let
|
|
|
|
|
cfg = config.security.duosec;
|
|
|
|
|
|
|
|
|
|
boolToStr = b: if b then "yes" else "no";
|
|
|
|
|
|
2019-02-13 02:39:22 +01:00
|
|
|
|
configFilePam = ''
|
2014-02-18 10:38:35 +01:00
|
|
|
|
[duo]
|
|
|
|
|
ikey=${cfg.ikey}
|
|
|
|
|
skey=${cfg.skey}
|
|
|
|
|
host=${cfg.host}
|
2020-01-30 20:16:17 +01:00
|
|
|
|
${optionalString (cfg.groups != "") ("groups="+cfg.groups)}
|
2014-02-18 10:38:35 +01:00
|
|
|
|
failmode=${cfg.failmode}
|
|
|
|
|
pushinfo=${boolToStr cfg.pushinfo}
|
|
|
|
|
autopush=${boolToStr cfg.autopush}
|
|
|
|
|
prompts=${toString cfg.prompts}
|
|
|
|
|
fallback_local_ip=${boolToStr cfg.fallbackLocalIP}
|
|
|
|
|
'';
|
|
|
|
|
|
2019-02-13 02:39:22 +01:00
|
|
|
|
configFileLogin = configFilePam + ''
|
|
|
|
|
motd=${boolToStr cfg.motd}
|
|
|
|
|
accept_env_factor=${boolToStr cfg.acceptEnvFactor}
|
|
|
|
|
'';
|
|
|
|
|
|
2019-09-14 19:51:29 +02:00
|
|
|
|
loginCfgFile = optionalAttrs cfg.ssh.enable {
|
|
|
|
|
"duo/login_duo.conf" =
|
|
|
|
|
{ source = pkgs.writeText "login_duo.conf" configFileLogin;
|
|
|
|
|
mode = "0600";
|
|
|
|
|
user = "sshd";
|
|
|
|
|
};
|
|
|
|
|
};
|
2014-02-18 10:38:35 +01:00
|
|
|
|
|
2019-09-14 19:51:29 +02:00
|
|
|
|
pamCfgFile = optional cfg.pam.enable {
|
|
|
|
|
"duo/pam_duo.conf" =
|
|
|
|
|
{ source = pkgs.writeText "pam_duo.conf" configFilePam;
|
|
|
|
|
mode = "0600";
|
|
|
|
|
user = "sshd";
|
|
|
|
|
};
|
|
|
|
|
};
|
2014-02-18 10:38:35 +01:00
|
|
|
|
in
|
|
|
|
|
{
|
2020-01-30 20:16:17 +01:00
|
|
|
|
imports = [
|
|
|
|
|
(mkRenamedOptionModule [ "security" "duosec" "group" ] [ "security" "duosec" "groups" ])
|
|
|
|
|
];
|
|
|
|
|
|
2014-02-18 10:38:35 +01:00
|
|
|
|
options = {
|
|
|
|
|
security.duosec = {
|
|
|
|
|
ssh.enable = mkOption {
|
|
|
|
|
type = types.bool;
|
|
|
|
|
default = false;
|
|
|
|
|
description = "If enabled, protect SSH logins with Duo Security.";
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
pam.enable = mkOption {
|
|
|
|
|
type = types.bool;
|
|
|
|
|
default = false;
|
|
|
|
|
description = "If enabled, protect logins with Duo Security using PAM support.";
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
ikey = mkOption {
|
|
|
|
|
type = types.str;
|
|
|
|
|
description = "Integration key.";
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
skey = mkOption {
|
|
|
|
|
type = types.str;
|
|
|
|
|
description = "Secret key.";
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
host = mkOption {
|
|
|
|
|
type = types.str;
|
|
|
|
|
description = "Duo API hostname.";
|
|
|
|
|
};
|
|
|
|
|
|
2020-01-30 20:16:17 +01:00
|
|
|
|
groups = mkOption {
|
2014-02-18 10:38:35 +01:00
|
|
|
|
type = types.str;
|
|
|
|
|
default = "";
|
2020-01-30 20:16:17 +01:00
|
|
|
|
example = "users,!wheel,!*admin guests";
|
|
|
|
|
description = ''
|
|
|
|
|
If specified, Duo authentication is required only for users
|
|
|
|
|
whose primary group or supplementary group list matches one
|
|
|
|
|
of the space-separated pattern lists. Refer to
|
|
|
|
|
<link xlink:href="https://duo.com/docs/duounix"/> for details.
|
|
|
|
|
'';
|
2014-02-18 10:38:35 +01:00
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
failmode = mkOption {
|
2019-03-18 02:25:20 +01:00
|
|
|
|
type = types.enum [ "safe" "secure" ];
|
2014-02-18 10:38:35 +01:00
|
|
|
|
default = "safe";
|
|
|
|
|
description = ''
|
|
|
|
|
On service or configuration errors that prevent Duo
|
|
|
|
|
authentication, fail "safe" (allow access) or "secure" (deny
|
|
|
|
|
access). The default is "safe".
|
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
pushinfo = mkOption {
|
|
|
|
|
type = types.bool;
|
|
|
|
|
default = false;
|
|
|
|
|
description = ''
|
|
|
|
|
Include information such as the command to be executed in
|
|
|
|
|
the Duo Push message.
|
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
autopush = mkOption {
|
|
|
|
|
type = types.bool;
|
|
|
|
|
default = false;
|
|
|
|
|
description = ''
|
|
|
|
|
If <literal>true</literal>, Duo Unix will automatically send
|
|
|
|
|
a push login request to the user’s phone, falling back on a
|
|
|
|
|
phone call if push is unavailable. If
|
|
|
|
|
<literal>false</literal>, the user will be prompted to
|
|
|
|
|
choose an authentication method. When configured with
|
|
|
|
|
<literal>autopush = yes</literal>, we recommend setting
|
|
|
|
|
<literal>prompts = 1</literal>.
|
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
motd = mkOption {
|
|
|
|
|
type = types.bool;
|
|
|
|
|
default = false;
|
|
|
|
|
description = ''
|
|
|
|
|
Print the contents of <literal>/etc/motd</literal> to screen
|
2014-12-30 03:31:03 +01:00
|
|
|
|
after a successful login.
|
2014-02-18 10:38:35 +01:00
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
prompts = mkOption {
|
2016-11-16 14:36:05 +01:00
|
|
|
|
type = types.enum [ 1 2 3 ];
|
2014-02-18 10:38:35 +01:00
|
|
|
|
default = 3;
|
|
|
|
|
description = ''
|
|
|
|
|
If a user fails to authenticate with a second factor, Duo
|
|
|
|
|
Unix will prompt the user to authenticate again. This option
|
|
|
|
|
sets the maximum number of prompts that Duo Unix will
|
|
|
|
|
display before denying access. Must be 1, 2, or 3. Default
|
|
|
|
|
is 3.
|
|
|
|
|
|
|
|
|
|
For example, when <literal>prompts = 1</literal>, the user
|
|
|
|
|
will have to successfully authenticate on the first prompt,
|
|
|
|
|
whereas if <literal>prompts = 2</literal>, if the user
|
|
|
|
|
enters incorrect information at the initial prompt, he/she
|
|
|
|
|
will be prompted to authenticate again.
|
|
|
|
|
|
|
|
|
|
When configured with <literal>autopush = true</literal>, we
|
|
|
|
|
recommend setting <literal>prompts = 1</literal>.
|
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
acceptEnvFactor = mkOption {
|
|
|
|
|
type = types.bool;
|
|
|
|
|
default = false;
|
|
|
|
|
description = ''
|
|
|
|
|
Look for factor selection or passcode in the
|
|
|
|
|
<literal>$DUO_PASSCODE</literal> environment variable before
|
|
|
|
|
prompting the user for input.
|
|
|
|
|
|
|
|
|
|
When $DUO_PASSCODE is non-empty, it will override
|
|
|
|
|
autopush. The SSH client will need SendEnv DUO_PASSCODE in
|
2014-12-30 03:31:03 +01:00
|
|
|
|
its configuration, and the SSH server will similarly need
|
2014-02-18 10:38:35 +01:00
|
|
|
|
AcceptEnv DUO_PASSCODE.
|
|
|
|
|
'';
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
fallbackLocalIP = mkOption {
|
|
|
|
|
type = types.bool;
|
|
|
|
|
default = false;
|
|
|
|
|
description = ''
|
|
|
|
|
Duo Unix reports the IP address of the authorizing user, for
|
|
|
|
|
the purposes of authorization and whitelisting. If Duo Unix
|
|
|
|
|
cannot detect the IP address of the client, setting
|
|
|
|
|
<literal>fallbackLocalIP = yes</literal> will cause Duo Unix
|
|
|
|
|
to send the IP address of the server it is running on.
|
|
|
|
|
|
|
|
|
|
If you are using IP whitelisting, enabling this option could
|
|
|
|
|
cause unauthorized logins if the local IP is listed in the
|
|
|
|
|
whitelist.
|
|
|
|
|
'';
|
|
|
|
|
};
|
2014-05-20 09:42:31 +02:00
|
|
|
|
|
|
|
|
|
allowTcpForwarding = mkOption {
|
|
|
|
|
type = types.bool;
|
|
|
|
|
default = false;
|
|
|
|
|
description = ''
|
|
|
|
|
By default, when SSH forwarding, enabling Duo Security will
|
|
|
|
|
disable TCP forwarding. By enabling this, you potentially
|
|
|
|
|
undermine some of the SSH based login security. Note this is
|
|
|
|
|
not needed if you use PAM.
|
|
|
|
|
'';
|
|
|
|
|
};
|
2014-02-18 10:38:35 +01:00
|
|
|
|
};
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
config = mkIf (cfg.ssh.enable || cfg.pam.enable) {
|
|
|
|
|
environment.systemPackages = [ pkgs.duo-unix ];
|
2016-07-16 02:10:48 +02:00
|
|
|
|
|
2017-01-29 12:33:56 +01:00
|
|
|
|
security.wrappers.login_duo.source = "${pkgs.duo-unix.out}/bin/login_duo";
|
2019-09-14 19:51:29 +02:00
|
|
|
|
environment.etc = loginCfgFile // pamCfgFile;
|
2014-02-18 10:38:35 +01:00
|
|
|
|
|
|
|
|
|
/* If PAM *and* SSH are enabled, then don't do anything special.
|
|
|
|
|
If PAM isn't used, set the default SSH-only options. */
|
|
|
|
|
services.openssh.extraConfig = mkIf (cfg.ssh.enable || cfg.pam.enable) (
|
|
|
|
|
if cfg.pam.enable then "UseDNS no" else ''
|
|
|
|
|
# Duo Security configuration
|
|
|
|
|
ForceCommand ${config.security.wrapperDir}/login_duo
|
|
|
|
|
PermitTunnel no
|
2014-05-20 09:42:31 +02:00
|
|
|
|
${optionalString (!cfg.allowTcpForwarding) ''
|
|
|
|
|
AllowTcpForwarding no
|
|
|
|
|
''}
|
2014-02-18 10:38:35 +01:00
|
|
|
|
'');
|
|
|
|
|
};
|
|
|
|
|
}
|