blob: f9e56bd3559f1aef4590352940f3ca1ca09478bd (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
|
# OpenSSH - Secure shell (SSH) client for encrypted remote connections
{
config,
lib,
pkgs,
...
}:
{
imports = [ ./git.nix ];
options.security.ssh = {
enable = lib.mkEnableOption "Enables ssh.";
};
config = lib.mkIf config.security.ssh.enable {
programs.ssh = {
enable = true;
package =
if (config.security.gopass.enable or false && config.security.gopass.ssh-agent.enable or false) then
pkgs.symlinkJoin {
name = "openssh-gopass-wrapper";
paths = [ pkgs.openssh ];
buildInputs = [ pkgs.makeWrapper ];
postBuild = ''
wrapProgram $out/bin/ssh \
--run "${lib.getExe config.scripts.gopass-ssh-load.package}"
'';
}
else
pkgs.openssh;
enableDefaultConfig = false;
extraOptionOverrides = {
AddKeysToAgent = "yes";
ForwardAgent = "yes";
ServerAliveInterval = "60";
ServerAliveCountMax = "3";
VisualHostKey = "yes";
HashKnownHosts = "yes";
};
};
services.ssh-agent.enable = lib.mkIf config.security.gpg.enable false;
};
}
|