1 {pkgs, lib, config, ...}:
2 let inherit (builtins) baseNameOf readFile;
4 inherit (config.services) openldap;
5 inherit (config.users) ldap;
6 unlines = lib.concatStringsSep "\n";
7 copyFile = file: pkgs.writeText (baseNameOf file) (readFile file);
8 configLDIF = pkgs.writeText "cn=config.ldif" (''
10 objectClass: olcGlobal
11 #olcPidFile: /run/slapd/slapd.pid
12 # List of arguments that were passed to the server
13 #olcArgsFile: /run/slapd/slapd.args
14 # Read slapd-config(5) for possible values
16 # The tool-threads parameter sets the actual amount of cpu's
17 # that is used for indexing.
20 dn: olcDatabase={-1}frontend,cn=config
21 objectClass: olcDatabaseConfig
22 objectClass: olcFrontendConfig
23 # The maximum number of entries that is returned for a search operation
25 # Allow unlimited access to local connection from the local root user
27 by dn.exact=gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth manage
29 # Allow unauthenticated read access for schema and base DN autodiscovery
30 olcAccess: to dn.exact=""
32 olcAccess: to dn.base="cn=Subschema"
35 dn: olcDatabase=config,cn=config
36 objectClass: olcDatabaseConfig
37 olcRootDN: cn=admin,cn=config
38 # Access to cn=config, system root can be manager
39 # with SASL mechanism (-Y EXTERNAL) over unix socket (-H ldapi://)
41 by dn.exact="gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth" manage
44 dn: cn=schema,cn=config
45 objectClass: olcSchemaConfig
47 include: file://${pkgs.openldap}/etc/schema/core.ldif
48 include: file://${pkgs.openldap}/etc/schema/cosine.ldif
49 include: file://${pkgs.openldap}/etc/schema/nis.ldif
50 include: file://${pkgs.openldap}/etc/schema/inetorgperson.ldif
51 include: file://${copyFile openldap/schema/postfix-book.ldif}
52 include: file://${copyFile openldap/schema/postfix2.ldif}
54 dn: cn=module{0},cn=config
55 objectClass: olcModuleList
56 # Where the dynamically loaded modules are stored
57 #olcModulePath: /usr/lib/ldap
58 olcModuleLoad: back_mdb
60 '' + unlines (lib.mapAttrsToList (olcSuffix: {conf, olcDbDirectory, ...}:
61 "include: file://" + pkgs.writeText "config.ldif" (conf + ''
62 olcSuffix: ${olcSuffix}
63 olcDbDirectory: ${olcDbDirectory}
65 ) openldap.databases));
69 openldap/commonsoft.coop.nix
71 options.services.openldap.domainSuffix = lib.mkOption {
73 default = "dc=${lib.concatStringsSep ",dc=" (lib.splitString "." config.networking.domain)}";
75 LDAP suffix for config.networking.domain.
78 options.services.openldap.databases = lib.mkOption {
79 type = types.attrsOf (types.submodule ({name, options, config, ...}: {
83 description = "The database's config in LDIF.";
87 description = "The database's data in LDIF.";
89 olcDbDirectory = lib.mkOption {
91 description = "The directory where the database is stored.";
92 default = "${openldap.dataDir}/${name}";
94 resetData = lib.mkOption {
96 description = "Whether to reset the data at each start of the slapd service.";
105 # FIXME: even with the correct LD_LIBRARY_PATH to libnss_ldap.so,
106 # passwd still does not work on LDAP accounts.
113 server = "ldapi:///";
114 base = "ou=posix,${openldap.domainSuffix}";
116 #distinguishedName = "cn=admin,${openldap.domainSuffix}";
119 services.openldap = {
121 dataDir = "/var/db/ldap";
122 configDir = "/var/db/slapd";
123 urlList = [ "ldapi:///" ]; # UNIX socket
125 systemd.services.openldap = {
127 # NOTE: slapd's config is always re-initialized.
128 rm -rf "${openldap.configDir}"/cn=config \
129 "${openldap.configDir}"/cn=config.ldif
130 install -D -d -m 0700 -o "${openldap.user}" -g "${openldap.group}" "${openldap.configDir}"
131 # NOTE: olcDbDirectory must be created before adding the config.
132 '' + unlines (lib.mapAttrsToList (olcSuffix: {data, olcDbDirectory, resetData, ...}:
133 lib.optionalString resetData ''
134 rm -rf "${olcDbDirectory}"
136 install -D -d -m 0700 -o "${openldap.user}" -g "${openldap.group}" "${olcDbDirectory}"
137 '') openldap.databases
139 # NOTE: slapd is supposed to be stopped while in preStart,
140 # hence slap* commands can safely be used.
142 ${pkgs.openldap}/bin/slapadd -n 0 \
143 -F "${openldap.configDir}" \
145 chown -R "${openldap.user}:${openldap.group}" "${openldap.configDir}"
146 # NOTE: slapadd(8): To populate the config database slapd-config(5),
147 # use -n 0 as it is always the first database.
148 # It must physically exist on the filesystem prior to this, however.
150 unlines (lib.mapAttrsToList (olcSuffix: {data, olcDbDirectory, resetData, ...}:
151 lib.optionalString resetData ''
152 ${pkgs.openldap}/bin/slapadd \
153 -F "${openldap.configDir}" \
154 -l ${pkgs.writeText "data.ldif" data}
156 test ! -e "${olcDbDirectory}" ||
157 chown -R "${openldap.user}:${openldap.group}" "${olcDbDirectory}"
158 '') openldap.databases);