fix(openconnect): ugent sso
This commit is contained in:
parent
6224eafa70
commit
b92a2fb821
7 changed files with 41 additions and 17 deletions
|
|
@ -19,7 +19,7 @@
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
networkmanager.enable = true;
|
networkmanager.enable = true;
|
||||||
openconnect-sso.enable = true;
|
openconnect.enable = true;
|
||||||
openvpn.enable = true;
|
openvpn.enable = true;
|
||||||
tailscale.enable = true;
|
tailscale.enable = true;
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -22,7 +22,7 @@
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
networkmanager.enable = true;
|
networkmanager.enable = true;
|
||||||
openconnect-sso.enable = true;
|
openconnect.enable = true;
|
||||||
tailscale.enable = true;
|
tailscale.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -25,7 +25,7 @@
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
networkmanager.enable = true;
|
networkmanager.enable = true;
|
||||||
#openconnect-sso.enable = true;
|
openconnect.enable = true;
|
||||||
openvpn.enable = true;
|
openvpn.enable = true;
|
||||||
tailscale.enable = true;
|
tailscale.enable = true;
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -1,7 +1,7 @@
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
./networkmanager
|
./networkmanager
|
||||||
./openconnect-sso
|
./openconnect
|
||||||
./openvpn
|
./openvpn
|
||||||
./tailscale
|
./tailscale
|
||||||
];
|
];
|
||||||
|
|
|
||||||
|
|
@ -1,13 +0,0 @@
|
||||||
{ config, inputs, lib, pkgs, ... }:
|
|
||||||
|
|
||||||
let
|
|
||||||
cfg = config.sisyphus.networking.openconnect-sso;
|
|
||||||
in {
|
|
||||||
options.sisyphus.networking.openconnect-sso.enable = lib.mkEnableOption "OpenConnect SSO";
|
|
||||||
|
|
||||||
config = lib.mkIf cfg.enable {
|
|
||||||
environment.systemPackages = with pkgs; [
|
|
||||||
inputs.openconnect-sso.packages.${config.nixpkgs.localSystem.system}.default
|
|
||||||
];
|
|
||||||
};
|
|
||||||
}
|
|
||||||
22
nixos/modules/networking/openconnect/default.nix
Normal file
22
nixos/modules/networking/openconnect/default.nix
Normal file
|
|
@ -0,0 +1,22 @@
|
||||||
|
{ config, inputs, lib, pkgs, ... }:
|
||||||
|
|
||||||
|
let
|
||||||
|
cfg = config.sisyphus.networking.openconnect;
|
||||||
|
|
||||||
|
ugentVpn = pkgs.writeShellApplication {
|
||||||
|
name = "ugent-vpn";
|
||||||
|
runtimeInputs = with pkgs; [
|
||||||
|
openconnect
|
||||||
|
];
|
||||||
|
text = builtins.readFile ./ugent-vpn.sh;
|
||||||
|
};
|
||||||
|
in {
|
||||||
|
options.sisyphus.networking.openconnect.enable = lib.mkEnableOption "OpenConnect";
|
||||||
|
|
||||||
|
config = lib.mkIf cfg.enable {
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
openconnect
|
||||||
|
ugentVpn
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}
|
||||||
15
nixos/modules/networking/openconnect/ugent-vpn.sh
Normal file
15
nixos/modules/networking/openconnect/ugent-vpn.sh
Normal file
|
|
@ -0,0 +1,15 @@
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -e
|
||||||
|
|
||||||
|
echo 'Starting UGent SSO authentication...'
|
||||||
|
eval "$( openconnect --authenticate --protocol=anyconnect vpn.ugent.be )"
|
||||||
|
|
||||||
|
if [ -z "${COOKIE}" ]; then
|
||||||
|
echo 'Authentication failed or was aborted.'
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo 'Authentication successful. Establishing tunnel...'
|
||||||
|
sudo openconnect --protocol=anyconnect --cookie="${COOKIE}" "${CONNECT_URL}" --servercert="${FINGERPRINT}" --resolve="${RESOLVE}"
|
||||||
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue