feat: everything perfect now trust me bro
This commit is contained in:
parent
6d8ce8772b
commit
45d9c2bf7d
1 changed files with 3 additions and 1 deletions
|
|
@ -42,10 +42,12 @@ in {
|
||||||
};
|
};
|
||||||
networking.firewall.allowedTCPPorts = [ 80 443 ];
|
networking.firewall.allowedTCPPorts = [ 80 443 ];
|
||||||
|
|
||||||
|
# Make certificate readable
|
||||||
|
users.users.nginx.extraGroups = [ "turnserver" ];
|
||||||
services.nginx.virtualHosts.${turn.realm} = {
|
services.nginx.virtualHosts.${turn.realm} = {
|
||||||
addSSL = true;
|
addSSL = true;
|
||||||
enableACME = false; # we’ll do ACME ourselves
|
enableACME = false; # we’ll do ACME ourselves
|
||||||
forceSSL = false;
|
forceSSL = true;
|
||||||
sslCertificate = "${config.security.acme.certs.${turn.realm}.directory}/full.pem";
|
sslCertificate = "${config.security.acme.certs.${turn.realm}.directory}/full.pem";
|
||||||
sslCertificateKey = "${config.security.acme.certs.${turn.realm}.directory}/key.pem";
|
sslCertificateKey = "${config.security.acme.certs.${turn.realm}.directory}/key.pem";
|
||||||
locations."/.well-known/acme-challenge/" = {
|
locations."/.well-known/acme-challenge/" = {
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue