blob: d6848d8da1f1e878a856cb44419226b0caf269c2 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
|
# gopass - Standard Unix password manager (Go implementation)
{
config,
lib,
pkgs,
...
}:
let
gopass-ssh-load = pkgs.writeShellScriptBin "gopass-ssh-load" ''
export SSH_AUTH_SOCK="$(${pkgs.gnupg}/bin/gpgconf --list-dirs agent-ssh-socket)"
if [ -z "$SSH_AUTH_SOCK" ] || [ ! -S "$SSH_AUTH_SOCK" ]; then
echo "Error: SSH_AUTH_SOCK is not set or valid." >&2
exit 1
fi
if ${pkgs.openssh}/bin/ssh-add -l 2>/dev/null | grep -qE "(ED25519|RSA|ECDSA)"; then
exit 0
fi
for key in github gitlab bitbucket codeberg sourcehut; do
if ${config.security.gopass.package}/bin/gopass cat "ssh/$key" > /dev/null 2>&1; then
tmpdir=$(mktemp -d)
keyfile="$tmpdir/key"
${config.security.gopass.package}/bin/gopass cat "ssh/$key" > "$keyfile" 2>/dev/null
chmod 600 "$keyfile"
if ! ${pkgs.openssh}/bin/ssh-add "$keyfile" 2>/dev/null; then
passphrase=$(${config.security.gopass.package}/bin/gopass cat "ssh/$key/passphrase" 2>/dev/null)
if [ -n "$passphrase" ]; then
tmpcopy=$(mktemp)
cp "$keyfile" "$tmpcopy"
chmod 600 "$tmpcopy"
if ${pkgs.openssh}/bin/ssh-keygen -p -P "$passphrase" -N "" -f "$tmpcopy" 2>/dev/null; then
${pkgs.openssh}/bin/ssh-add "$tmpcopy" 2>/dev/null
fi
rm -f "$tmpcopy"
fi
fi
rm -rf "$tmpdir"
fi
done
'';
in
{
options.security.gopass = {
enable = lib.mkEnableOption "Enables gopass.";
package = lib.mkOption {
type = lib.types.package;
default = pkgs.gopass.override { passAlias = true; };
defaultText = lib.literalExpression "pkgs.gopass.override { passAlias = true; }";
description = "The gopass package to use.";
};
ssh-agent = {
enable = lib.mkEnableOption "gopass-backed SSH keys for git";
script = lib.mkOption {
type = lib.types.package;
description = "The package containing the gopass-ssh-load script.";
};
};
};
config = lib.mkIf config.security.gopass.enable {
security.gopass.ssh-agent.script = gopass-ssh-load;
programs.password-store = {
enable = true;
package = config.security.gopass.package;
settings = {
PASSWORD_STORE_DIR = "${config.home.homeDirectory}/.local/share/pass";
};
};
home.sessionVariables = {
PASSWORD_STORE_DIR = config.programs.password-store.settings.PASSWORD_STORE_DIR;
};
home.packages = lib.mkIf config.security.gopass.ssh-agent.enable [
config.security.gopass.ssh-agent.script
];
};
}
|