summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rwxr-xr-xhome.nix13
-rwxr-xr-xhome/shell.nix131
-rw-r--r--home/ssh.nix17
3 files changed, 148 insertions, 13 deletions
diff --git a/home.nix b/home.nix
index c77f352..3960144 100755
--- a/home.nix
+++ b/home.nix
@@ -22,12 +22,25 @@ in
./home/vcs.nix
]
++ lib.optionals (host.name == "turing") [
+ (import ./home/ssh.nix {
+ principals = [
+ "t:human"
+ "h:turing"
+ ];
+ })
./home/packages.nix
./home/typst.nix
./home/pkgs_mac.nix
./home/ghostty.nix
+
]
++ lib.optionals (lib.hasSuffix "cs.purdue.edu" host.name) [
+ (import ./home/ssh.nix {
+ principals = [
+ "t:human"
+ "h:purdue"
+ ];
+ })
./home/cs_purdue.nix
./home/typst.nix
];
diff --git a/home/shell.nix b/home/shell.nix
index f98de94..d3f9ccd 100755
--- a/home/shell.nix
+++ b/home/shell.nix
@@ -33,19 +33,22 @@ in
openssh
openssl
- ((import "${tpbSrc}/default.nix" {
- inherit pkgs;
- }).overrideAttrs (_: {
- unpackPhase = ''
- mkdir source
- tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \
- -C "$src" -cf - . \
- | tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \
- -C source -xf -
- chmod -R u+w source
- sourceRoot=source
- '';
- }))
+ (
+ (import "${tpbSrc}/default.nix" {
+ inherit pkgs;
+ }).overrideAttrs
+ (_: {
+ unpackPhase = ''
+ mkdir source
+ tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \
+ -C "$src" -cf - . \
+ | tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \
+ -C source -xf -
+ chmod -R u+w source
+ sourceRoot=source
+ '';
+ })
+ )
];
xdg.configFile."fish/themes/rose_pine.theme".source =
@@ -170,6 +173,108 @@ in
command nix $argv
'';
};
+
+ sshsignkey = ''
+ argparse \
+ 't/tag=+' \
+ 'h/host=' \
+ 'u/user=' \
+ 'I/identity=' \
+ 'V/validity=' \
+ -- $argv
+ or return 2
+
+ if test (count $argv) -ne 1
+ echo "usage: sshsignkey [-t TAG ...] [-h HOST] [-u USER] [-I ID] [-V VALIDITY] 'PUBLIC KEY'" >&2
+ return 2
+ end
+
+ set -l ca_pub ~/.ssh/ssh-ca.pub
+ set -l principals
+
+ for tag in $_flag_tag
+ set -a principals "t:$tag"
+ end
+
+ if set -q _flag_host
+ set -a principals "h:$_flag_host"
+ end
+
+ if set -q _flag_user
+ set -a principals "u:$_flag_user"
+ end
+
+ if test (count $principals) -eq 0
+ echo "sshsignkey: at least one principal is required" >&2
+ return 2
+ end
+
+ if set -q _flag_identity
+ set -l identity "$_flag_identity"
+ else if set -q _flag_user; and set -q _flag_host
+ set -l identity "$_flag_user@$_flag_host"
+ else if set -q _flag_user
+ set -l identity "$_flag_user"
+ else if set -q _flag_host
+ set -l identity "$_flag_host"
+ else
+ set -l identity "ssh-cert"
+ end
+
+ if not test -f "$ca_pub"
+ echo "sshsignkey: CA public key not found: $ca_pub" >&2
+ return 1
+ end
+
+ set -l pivroot (dirname (dirname "${pkgs.yubico-piv-tool}/bin/yubico-piv-tool"))
+
+ set -l ykcs11 (
+ ${pkgs.findutils}/bin/find "$pivroot" \
+ -name 'libykcs11.dylib' \
+ -o -name 'libykcs11.so' \
+ | ${pkgs.coreutils}/bin/head -n1
+ )
+
+ if test -z "$ykcs11"
+ echo "sshsignkey: could not find libykcs11" >&2
+ return 1
+ end
+
+ set -l tmpdir (${pkgs.coreutils}/bin/mktemp -d)
+ or return 1
+
+ set -l pubfile "$tmpdir/key.pub"
+ printf '%s\n' "$argv[1]" > "$pubfile"
+
+ set -l ssh_args \
+ -s "$ca_pub" \
+ -D "$ykcs11" \
+ -I "$identity" \
+ -n (string join ',' $principals)
+
+ if set -q _flag_validity
+ set -a ssh_args -V "$_flag_validity"
+ end
+
+ set -lx SSH_ASKPASS_REQUIRE force
+ set -lx SSH_ASKPASS ${pkgs.writeShellScript "yubikey-verify-none" ''
+ printf '%s\n' VERIFY_NONE
+ ''}
+
+ echo "Touch your YubiKey to sign the SSH certificate..." >&2
+
+ ${pkgs.openssh}/bin/ssh-keygen $ssh_args "$pubfile" >/dev/null
+ set -l rc $status
+
+ if test $rc -ne 0
+ ${pkgs.coreutils}/bin/rm -rf "$tmpdir"
+ return $rc
+ end
+
+ ${pkgs.coreutils}/bin/cat "$tmpdir/key-cert.pub"
+
+ ${pkgs.coreutils}/bin/rm -rf "$tmpdir"
+ '';
};
interactiveShellInit = ''
diff --git a/home/ssh.nix b/home/ssh.nix
new file mode 100644
index 0000000..f0e75c7
--- /dev/null
+++ b/home/ssh.nix
@@ -0,0 +1,17 @@
+{
+ principals,
+ extraKeys ? [ ],
+}:
+
+{
+ lib,
+ ...
+}:
+
+{
+ home.file.".ssh/authorized_keys".text = ''
+ cert-authority,principals="${lib.concatStringsSep "," principals}" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink
+ sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIA6Eq2yVsZrCH8so7f3ygH0UWp6WkOxbhLNFC9QewKwoAAAABHNzaDo= grace.pink
+ ${lib.concatStringsSep "\n" extraKeys}
+ '';
+}