From 96ec0f89101ea414e764565e022b9bc83a96071c Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Thu, 10 Sep 2026 04:32:33 +0530 Subject: fix(security/ssh): fixed the loading ssh key from gopass Now on every home-manager switch we run a script that loads the key form gopass to gpg-agent, then the gpg-agent is responsible for storing it. Anytime gopass changes the ssh key we must run home-manager switch to load the ssh key into gpg agent. --- users/arpit/default.nix | 1 - users/arpit/private.example.nix | 7 ++----- 2 files changed, 2 insertions(+), 6 deletions(-) (limited to 'users') diff --git a/users/arpit/default.nix b/users/arpit/default.nix index 9348884..e21b280 100644 --- a/users/arpit/default.nix +++ b/users/arpit/default.nix @@ -65,7 +65,6 @@ # Security security.gopass.enable = true; - security.gopass.ssh-agent.enable = true; security.gopass.sync.enable = true; security.gpg.enable = true; security.gpg.backup.enable = true; diff --git a/users/arpit/private.example.nix b/users/arpit/private.example.nix index 77e5f54..2f169d9 100644 --- a/users/arpit/private.example.nix +++ b/users/arpit/private.example.nix @@ -38,11 +38,8 @@ }; }; - # SSH keys to load from gopass (entries under ssh/ in the gopass store) - config.security.ssh.gopassKeys = [ - "github" - "gitlab" - ]; + # SSH key to load into the gpg-agent from gopass (entry in the gopass store) + config.security.ssh.sshKeyGopassPath = "ssh/hostname/username"; # Gopass - Template for configuring gopass, specially syncing config.security.gopass.sync = { -- cgit v1.2.3