blob: 62186c46c2a5a867609741fd7776630e196d7022 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
|
# OpenSSH - Secure shell (SSH) client for encrypted remote connections
{
config,
lib,
pkgs,
...
}:
{
imports = [ ./git.nix ];
options.security.ssh = {
enable = lib.mkEnableOption "Enables ssh.";
};
config = lib.mkIf config.security.ssh.enable {
programs.ssh = {
enable = true;
package =
if (config.security.gopass.enable or false && config.security.gopass.ssh-agent.enable or false) then
pkgs.symlinkJoin {
name = "openssh-gopass-wrapper";
paths = [ pkgs.openssh ];
buildInputs = [ pkgs.makeWrapper ];
postBuild = ''
wrapProgram $out/bin/ssh \
--run "${config.security.gopass.ssh-agent.script}/bin/gopass-ssh-load"
'';
}
else
pkgs.openssh;
enableDefaultConfig = false;
extraOptionOverrides = {
AddKeysToAgent = "yes";
ForwardAgent = "yes";
ServerAliveInterval = "60";
ServerAliveCountMax = "3";
VisualHostKey = "yes";
HashKnownHosts = "yes";
};
};
services.ssh-agent.enable = lib.mkIf config.security.gpg.enable false;
};
}
|