v0.0.6 - Tier-1 TCP listener + FIPS deployment documentation
This commit is contained in:
17
packaging/qubes/install-policy.sh
Normal file
17
packaging/qubes/install-policy.sh
Normal file
@@ -0,0 +1,17 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
POLICY_SRC="packaging/qubes/policy.d/40-nsigner.policy"
|
||||
POLICY_DST="/etc/qubes/policy.d/40-nsigner.policy"
|
||||
|
||||
if [ ! -f "$POLICY_SRC" ]; then
|
||||
echo "Missing policy source: $POLICY_SRC" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
install -m 0644 "$POLICY_SRC" "$POLICY_DST"
|
||||
|
||||
echo "Installed qrexec policy to $POLICY_DST"
|
||||
echo "Tag your signer qube in dom0, for example:"
|
||||
echo " qvm-tags nsigner-vault add nsigner-signer"
|
||||
echo "Then reload policy per your Qubes OS version procedures."
|
||||
15
packaging/qubes/install-service.sh
Normal file
15
packaging/qubes/install-service.sh
Normal file
@@ -0,0 +1,15 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
SERVICE_SRC="packaging/qubes/rpc/qubes.NsignerRpc"
|
||||
SERVICE_DST="/etc/qubes-rpc/qubes.NsignerRpc"
|
||||
|
||||
if [ ! -f "$SERVICE_SRC" ]; then
|
||||
echo "Missing service source: $SERVICE_SRC" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
install -m 0755 "$SERVICE_SRC" "$SERVICE_DST"
|
||||
|
||||
echo "Installed qrexec service to $SERVICE_DST"
|
||||
echo "Executable bit set via install -m 0755."
|
||||
5
packaging/qubes/policy.d/40-nsigner.policy
Normal file
5
packaging/qubes/policy.d/40-nsigner.policy
Normal file
@@ -0,0 +1,5 @@
|
||||
# Qubes OS qrexec policy for nsigner
|
||||
# Syntax: service +argument source target action
|
||||
# Allow specific qubes to reach the signer qube with user confirmation
|
||||
qubes.NsignerRpc * @anyvm @tag:nsigner-signer ask default_target=nsigner-vault
|
||||
qubes.NsignerRpc * @anyvm @anyvm deny
|
||||
2
packaging/qubes/rpc/qubes.NsignerRpc
Normal file
2
packaging/qubes/rpc/qubes.NsignerRpc
Normal file
@@ -0,0 +1,2 @@
|
||||
#!/bin/sh
|
||||
exec /usr/local/bin/nsigner --listen qrexec
|
||||
Reference in New Issue
Block a user