blob: 8d1f88176a23a8bf36bf79c9f98169160362ca71 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
|
# Secure shell client for encrypted remote connections
{
config,
lib,
pkgs,
...
}:
{
options.security.ssh = {
enable = lib.mkEnableOption "Enables ssh.";
package = lib.mkOption {
type = lib.types.package;
readOnly = true;
default = config.programs.ssh.package;
description = "The ssh package to use.";
};
gopassKeys = lib.mkOption {
type = lib.types.listOf lib.types.str;
default = [ ];
description = "SSH keys to load from the gopass store (entries under ssh/).";
};
};
config = lib.mkIf config.security.ssh.enable {
programs.ssh = {
enable = true;
package = pkgs.openssh;
enableDefaultConfig = false;
extraOptionOverrides = {
AddKeysToAgent = "yes";
ForwardAgent = "yes";
ServerAliveInterval = "60";
ServerAliveCountMax = "3";
VisualHostKey = "yes";
HashKnownHosts = "yes";
};
};
services.ssh-agent.enable = lib.mkIf config.security.gpg.enable false;
};
}
|