summaryrefslogtreecommitdiff
path: root/home
diff options
context:
space:
mode:
authorGrace Yoder <grace_yoder@outlook.com>2026-09-30 17:26:38 -0400
committerGrace Yoder <grace_yoder@outlook.com>2026-10-02 13:24:29 -0400
commitf3336037e87ec4f97c00397cc81fec5e245ea4f5 (patch)
tree540788453e79913739e2e0d6f6d87937148f439f /home
parentab6f8b3f945bf4b532e01b9585a2e228ac332c42 (diff)
added ssh cert stuff
Diffstat (limited to 'home')
-rwxr-xr-xhome/shell.nix131
-rw-r--r--home/ssh.nix17
2 files changed, 135 insertions, 13 deletions
diff --git a/home/shell.nix b/home/shell.nix
index f98de94..d3f9ccd 100755
--- a/home/shell.nix
+++ b/home/shell.nix
@@ -33,19 +33,22 @@ in
openssh
openssl
- ((import "${tpbSrc}/default.nix" {
- inherit pkgs;
- }).overrideAttrs (_: {
- unpackPhase = ''
- mkdir source
- tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \
- -C "$src" -cf - . \
- | tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \
- -C source -xf -
- chmod -R u+w source
- sourceRoot=source
- '';
- }))
+ (
+ (import "${tpbSrc}/default.nix" {
+ inherit pkgs;
+ }).overrideAttrs
+ (_: {
+ unpackPhase = ''
+ mkdir source
+ tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \
+ -C "$src" -cf - . \
+ | tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \
+ -C source -xf -
+ chmod -R u+w source
+ sourceRoot=source
+ '';
+ })
+ )
];
xdg.configFile."fish/themes/rose_pine.theme".source =
@@ -170,6 +173,108 @@ in
command nix $argv
'';
};
+
+ sshsignkey = ''
+ argparse \
+ 't/tag=+' \
+ 'h/host=' \
+ 'u/user=' \
+ 'I/identity=' \
+ 'V/validity=' \
+ -- $argv
+ or return 2
+
+ if test (count $argv) -ne 1
+ echo "usage: sshsignkey [-t TAG ...] [-h HOST] [-u USER] [-I ID] [-V VALIDITY] 'PUBLIC KEY'" >&2
+ return 2
+ end
+
+ set -l ca_pub ~/.ssh/ssh-ca.pub
+ set -l principals
+
+ for tag in $_flag_tag
+ set -a principals "t:$tag"
+ end
+
+ if set -q _flag_host
+ set -a principals "h:$_flag_host"
+ end
+
+ if set -q _flag_user
+ set -a principals "u:$_flag_user"
+ end
+
+ if test (count $principals) -eq 0
+ echo "sshsignkey: at least one principal is required" >&2
+ return 2
+ end
+
+ if set -q _flag_identity
+ set -l identity "$_flag_identity"
+ else if set -q _flag_user; and set -q _flag_host
+ set -l identity "$_flag_user@$_flag_host"
+ else if set -q _flag_user
+ set -l identity "$_flag_user"
+ else if set -q _flag_host
+ set -l identity "$_flag_host"
+ else
+ set -l identity "ssh-cert"
+ end
+
+ if not test -f "$ca_pub"
+ echo "sshsignkey: CA public key not found: $ca_pub" >&2
+ return 1
+ end
+
+ set -l pivroot (dirname (dirname "${pkgs.yubico-piv-tool}/bin/yubico-piv-tool"))
+
+ set -l ykcs11 (
+ ${pkgs.findutils}/bin/find "$pivroot" \
+ -name 'libykcs11.dylib' \
+ -o -name 'libykcs11.so' \
+ | ${pkgs.coreutils}/bin/head -n1
+ )
+
+ if test -z "$ykcs11"
+ echo "sshsignkey: could not find libykcs11" >&2
+ return 1
+ end
+
+ set -l tmpdir (${pkgs.coreutils}/bin/mktemp -d)
+ or return 1
+
+ set -l pubfile "$tmpdir/key.pub"
+ printf '%s\n' "$argv[1]" > "$pubfile"
+
+ set -l ssh_args \
+ -s "$ca_pub" \
+ -D "$ykcs11" \
+ -I "$identity" \
+ -n (string join ',' $principals)
+
+ if set -q _flag_validity
+ set -a ssh_args -V "$_flag_validity"
+ end
+
+ set -lx SSH_ASKPASS_REQUIRE force
+ set -lx SSH_ASKPASS ${pkgs.writeShellScript "yubikey-verify-none" ''
+ printf '%s\n' VERIFY_NONE
+ ''}
+
+ echo "Touch your YubiKey to sign the SSH certificate..." >&2
+
+ ${pkgs.openssh}/bin/ssh-keygen $ssh_args "$pubfile" >/dev/null
+ set -l rc $status
+
+ if test $rc -ne 0
+ ${pkgs.coreutils}/bin/rm -rf "$tmpdir"
+ return $rc
+ end
+
+ ${pkgs.coreutils}/bin/cat "$tmpdir/key-cert.pub"
+
+ ${pkgs.coreutils}/bin/rm -rf "$tmpdir"
+ '';
};
interactiveShellInit = ''
diff --git a/home/ssh.nix b/home/ssh.nix
new file mode 100644
index 0000000..f0e75c7
--- /dev/null
+++ b/home/ssh.nix
@@ -0,0 +1,17 @@
+{
+ principals,
+ extraKeys ? [ ],
+}:
+
+{
+ lib,
+ ...
+}:
+
+{
+ home.file.".ssh/authorized_keys".text = ''
+ cert-authority,principals="${lib.concatStringsSep "," principals}" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink
+ sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIA6Eq2yVsZrCH8so7f3ygH0UWp6WkOxbhLNFC9QewKwoAAAABHNzaDo= grace.pink
+ ${lib.concatStringsSep "\n" extraKeys}
+ '';
+}