NixOS / nixpkgs

Nix Packages collection & NixOS
MIT License
16.51k stars 12.99k forks source link

ACME support for systemd credentials #206020

Open pca006132 opened 1 year ago

pca006132 commented 1 year ago

Issue description

Systemd supports credential which will place the credential in non-swappable memory, with access restriction, and supports encryption with TPM2 chip. It would be nice if ACME can add some related configurations to allow users to use this functionality. Adding LoadCredentialEncrypted or SetCredentialEncrypted to systemd.services.<name>.serviceConfig should suffice.

Notify Maintainers

@NixOS/acme

LiGoldragon commented 10 months ago

https://github.com/korfuri/agenix-systemd