summaryrefslogtreecommitdiff
path: root/pkgs/development/python-modules/rangehttpserver
diff options
context:
space:
mode:
authorLin Jian <me@linj.tech>2022-06-26 13:19:10 +0800
committerLin Jian <me@linj.tech>2022-06-29 05:41:13 +0800
commitf7baa65db75b32db49894296646a1b9b74115482 (patch)
treec389d071bf06a6067ca1a3eb7dc0c5d7b253f8b4 /pkgs/development/python-modules/rangehttpserver
parent608607c4107939a2f106ebe7ad619454f3003d9d (diff)
nixos/caddy: improve security about acme certs
Before this patch, the caddy process has acme in its supplementary group because of the SupplementaryGroups in its service config, which may give it more permission than needed, is inconsistent with the documentation of services.caddy.virtualHosts.<name>.useACMEHost and is redundant since we have mkCertOwnershipAssertion in assertions. This patch fixes these problems by defaulting the group of needed certs to caddy, which is what other web servers like nginx do and deleting SupplementaryGroups config.
Diffstat (limited to 'pkgs/development/python-modules/rangehttpserver')
0 files changed, 0 insertions, 0 deletions