* Provide a bundle of CA certificates in /etc/ca-bundle.crt, and set

the CURL_CA_BUNDLE environment variable.  This allows curl to work
  without the `-k' flag on https sites with a properly signed
  certificate.

svn path=/nixos/trunk/; revision=19572
wip/yesman
Eelco Dolstra 15 years ago
parent 6502806689
commit 8a6346e477
  1. 1
      modules/module-list.nix
  2. 21
      modules/security/ca.nix

@ -31,6 +31,7 @@
./programs/ssh.nix
./programs/ssmtp.nix
./rename.nix
./security/ca.nix
./security/consolekit.nix
./security/pam.nix
./security/pam_usb.nix

@ -0,0 +1,21 @@
{ config, pkgs, ... }:
with pkgs.lib;
{
config = {
environment.etc = singleton
{ source = "${pkgs.cacert}/etc/ca-bundle.crt";
target = "ca-bundle.crt";
};
environment.shellInit =
''
export CURL_CA_BUNDLE=/etc/ca-bundle.crt
'';
};
}
Loading…
Cancel
Save