diff --git a/README.md b/README.md index 735e88f..5eb3e65 100644 --- a/README.md +++ b/README.md @@ -35,6 +35,9 @@ NixOS + Home Manager ## Declarative Defeat Necessary configurations not achievable with dotfiles +### Profile: cli-minimal +- SSH key registration + Please register the value of ~/.ssh/id_ed25519.pub on GitHub. ### Profile: laptop - Fingerprint registration Please register the user's fingerprints by running fprintd-enroll. diff --git a/flake.nix b/flake.nix index 243a94a..a99b0d2 100644 --- a/flake.nix +++ b/flake.nix @@ -13,7 +13,6 @@ vicinae.url = "github:vicinaehq/vicinae"; ghostty.url = "github:ghostty-org/ghostty"; - auth-keys-hub.url = "github:input-output-hk/auth-keys-hub"; quickshell = { url = "github:outfoxxed/quickshell"; diff --git a/modules/core/ssh.nix b/modules/core/ssh.nix index 11e4f1b..8a2a383 100644 --- a/modules/core/ssh.nix +++ b/modules/core/ssh.nix @@ -1,24 +1,15 @@ -{ inputs, pkgs, ... }: +{ pkgs, ... }: { - imports = [ inputs.auth-keys-hub.nixosModules.auth-keys-hub ]; - - programs.ssh.startAgent = true; services.openssh = { enable = true; openFirewall = true; settings = { - PermitRootLogin = "no"; # Prevent root from SSH login + PermitRootLogin = "no"; PasswordAuthentication = false; - KbdInteractiveAuthentication = true; + KbdInteractiveAuthentication = false; + PubkeyAuthentication = "yes"; }; - ports = [ 22 ]; }; - programs.auth-keys-hub = { - enable = true; - github = { - users = [ "moons-14:moons" ]; - }; - }; } diff --git a/modules/home/ssh.nix b/modules/home/ssh.nix index 257ee12..6cfaf48 100644 --- a/modules/home/ssh.nix +++ b/modules/home/ssh.nix @@ -8,20 +8,28 @@ if [ ! -f "$key" ]; then umask 077 mkdir -p "$HOME/.ssh" - ssh-keygen -t ed25519 -N "" -f "$key" \ - -C "${config.home.username}@$(hostnamectl --static)" + ssh-keygen -t ed25519 -N "" -f "$key" -C "moons@$(hostnamectl --static 2>/dev/null || echo host)" echo "Generated SSH key at $key" - echo "Public key:" - cat "$key.pub" fi ''; - services.ssh-agent.enable = true; - programs.gpg.enable = true; + home.file.".ssh/config".text = '' + Host * + AddKeysToAgent yes + IdentityFile ~/.ssh/id_ed25519 + ''; - - services.gpg-agent = { + programs.git = { enable = true; - enableSshSupport = true; + + signing = { + key = "~/.ssh/id_ed25519.pub"; + signByDefault = true; + }; + + extraConfig = { + gpg.format = "ssh"; + tag.gpgSign = true; + }; }; }