From f3336037e87ec4f97c00397cc81fec5e245ea4f5 Mon Sep 17 00:00:00 2001 From: Grace Yoder Date: Wed, 30 Sep 2026 17:26:38 -0400 Subject: added ssh cert stuff --- home.nix | 13 ++++++ home/shell.nix | 131 +++++++++++++++++++++++++++++++++++++++++++++++++++------ home/ssh.nix | 17 ++++++++ 3 files changed, 148 insertions(+), 13 deletions(-) create mode 100644 home/ssh.nix diff --git a/home.nix b/home.nix index c77f352..3960144 100755 --- a/home.nix +++ b/home.nix @@ -22,12 +22,25 @@ in ./home/vcs.nix ] ++ lib.optionals (host.name == "turing") [ + (import ./home/ssh.nix { + principals = [ + "t:human" + "h:turing" + ]; + }) ./home/packages.nix ./home/typst.nix ./home/pkgs_mac.nix ./home/ghostty.nix + ] ++ lib.optionals (lib.hasSuffix "cs.purdue.edu" host.name) [ + (import ./home/ssh.nix { + principals = [ + "t:human" + "h:purdue" + ]; + }) ./home/cs_purdue.nix ./home/typst.nix ]; diff --git a/home/shell.nix b/home/shell.nix index f98de94..d3f9ccd 100755 --- a/home/shell.nix +++ b/home/shell.nix @@ -33,19 +33,22 @@ in openssh openssl - ((import "${tpbSrc}/default.nix" { - inherit pkgs; - }).overrideAttrs (_: { - unpackPhase = '' - mkdir source - tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \ - -C "$src" -cf - . \ - | tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \ - -C source -xf - - chmod -R u+w source - sourceRoot=source - ''; - })) + ( + (import "${tpbSrc}/default.nix" { + inherit pkgs; + }).overrideAttrs + (_: { + unpackPhase = '' + mkdir source + tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \ + -C "$src" -cf - . \ + | tar --no-same-owner --no-same-permissions --no-overwrite-dir --mode=0755 \ + -C source -xf - + chmod -R u+w source + sourceRoot=source + ''; + }) + ) ]; xdg.configFile."fish/themes/rose_pine.theme".source = @@ -170,6 +173,108 @@ in command nix $argv ''; }; + + sshsignkey = '' + argparse \ + 't/tag=+' \ + 'h/host=' \ + 'u/user=' \ + 'I/identity=' \ + 'V/validity=' \ + -- $argv + or return 2 + + if test (count $argv) -ne 1 + echo "usage: sshsignkey [-t TAG ...] [-h HOST] [-u USER] [-I ID] [-V VALIDITY] 'PUBLIC KEY'" >&2 + return 2 + end + + set -l ca_pub ~/.ssh/ssh-ca.pub + set -l principals + + for tag in $_flag_tag + set -a principals "t:$tag" + end + + if set -q _flag_host + set -a principals "h:$_flag_host" + end + + if set -q _flag_user + set -a principals "u:$_flag_user" + end + + if test (count $principals) -eq 0 + echo "sshsignkey: at least one principal is required" >&2 + return 2 + end + + if set -q _flag_identity + set -l identity "$_flag_identity" + else if set -q _flag_user; and set -q _flag_host + set -l identity "$_flag_user@$_flag_host" + else if set -q _flag_user + set -l identity "$_flag_user" + else if set -q _flag_host + set -l identity "$_flag_host" + else + set -l identity "ssh-cert" + end + + if not test -f "$ca_pub" + echo "sshsignkey: CA public key not found: $ca_pub" >&2 + return 1 + end + + set -l pivroot (dirname (dirname "${pkgs.yubico-piv-tool}/bin/yubico-piv-tool")) + + set -l ykcs11 ( + ${pkgs.findutils}/bin/find "$pivroot" \ + -name 'libykcs11.dylib' \ + -o -name 'libykcs11.so' \ + | ${pkgs.coreutils}/bin/head -n1 + ) + + if test -z "$ykcs11" + echo "sshsignkey: could not find libykcs11" >&2 + return 1 + end + + set -l tmpdir (${pkgs.coreutils}/bin/mktemp -d) + or return 1 + + set -l pubfile "$tmpdir/key.pub" + printf '%s\n' "$argv[1]" > "$pubfile" + + set -l ssh_args \ + -s "$ca_pub" \ + -D "$ykcs11" \ + -I "$identity" \ + -n (string join ',' $principals) + + if set -q _flag_validity + set -a ssh_args -V "$_flag_validity" + end + + set -lx SSH_ASKPASS_REQUIRE force + set -lx SSH_ASKPASS ${pkgs.writeShellScript "yubikey-verify-none" '' + printf '%s\n' VERIFY_NONE + ''} + + echo "Touch your YubiKey to sign the SSH certificate..." >&2 + + ${pkgs.openssh}/bin/ssh-keygen $ssh_args "$pubfile" >/dev/null + set -l rc $status + + if test $rc -ne 0 + ${pkgs.coreutils}/bin/rm -rf "$tmpdir" + return $rc + end + + ${pkgs.coreutils}/bin/cat "$tmpdir/key-cert.pub" + + ${pkgs.coreutils}/bin/rm -rf "$tmpdir" + ''; }; interactiveShellInit = '' diff --git a/home/ssh.nix b/home/ssh.nix new file mode 100644 index 0000000..f0e75c7 --- /dev/null +++ b/home/ssh.nix @@ -0,0 +1,17 @@ +{ + principals, + extraKeys ? [ ], +}: + +{ + lib, + ... +}: + +{ + home.file.".ssh/authorized_keys".text = '' + cert-authority,principals="${lib.concatStringsSep "," principals}" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuc4HCdyEMu4uiYhlokSXmu+68hkm7j6CqVwjDkCeSj grace.pink + sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIA6Eq2yVsZrCH8so7f3ygH0UWp6WkOxbhLNFC9QewKwoAAAABHNzaDo= grace.pink + ${lib.concatStringsSep "\n" extraKeys} + ''; +} -- cgit v1.3.1