From 8b5e5079e5fd00eadf2e3926c104e4ecf99a5779 Mon Sep 17 00:00:00 2001 From: Fuwn Date: Wed, 4 Sep 2024 19:57:20 -0700 Subject: refac --- modules/system/access/default.nix | 7 +++++++ modules/system/access/gnupg.nix | 16 ++++++++++++++++ modules/system/access/mosh.nix | 6 ++++++ modules/system/access/ssh.nix | 26 ++++++++++++++++++++++++++ 4 files changed, 55 insertions(+) create mode 100644 modules/system/access/default.nix create mode 100644 modules/system/access/gnupg.nix create mode 100644 modules/system/access/mosh.nix create mode 100644 modules/system/access/ssh.nix (limited to 'modules/system/access') diff --git a/modules/system/access/default.nix b/modules/system/access/default.nix new file mode 100644 index 0000000..7db7629 --- /dev/null +++ b/modules/system/access/default.nix @@ -0,0 +1,7 @@ +{ + imports = [ + ./gnupg.nix + ./mosh.nix + ./ssh.nix + ]; +} diff --git a/modules/system/access/gnupg.nix b/modules/system/access/gnupg.nix new file mode 100644 index 0000000..aeffb23 --- /dev/null +++ b/modules/system/access/gnupg.nix @@ -0,0 +1,16 @@ +{ pkgs, ... }: +{ + programs.gnupg.agent = { + enable = true; + enableSSHSupport = true; + pinentryPackage = pkgs.pinentry-curses; + + settings = { + enable-ssh-support = ""; + ttyname = "$GPG_TTY"; + default-cache-ttl = 34560000; # 60 + max-cache-ttl = 34560000; # 120 + allow-loopback-pinentry = ""; + }; + }; +} diff --git a/modules/system/access/mosh.nix b/modules/system/access/mosh.nix new file mode 100644 index 0000000..c9af5bf --- /dev/null +++ b/modules/system/access/mosh.nix @@ -0,0 +1,6 @@ +{ + programs.mosh = { + enable = true; + openFirewall = false; + }; +} diff --git a/modules/system/access/ssh.nix b/modules/system/access/ssh.nix new file mode 100644 index 0000000..b1fc187 --- /dev/null +++ b/modules/system/access/ssh.nix @@ -0,0 +1,26 @@ +{ + programs.ssh.startAgent = false; + + services.openssh = { + enable = true; + ports = [ 22 ]; + openFirewall = false; + + settings = { + KexAlgorithms = [ + "curve25519-sha256" + "curve25519-sha256@libssh.org" + "diffie-hellman-group16-sha512" + "diffie-hellman-group18-sha512" + "diffie-hellman-group-exchange-sha256" + "sntrup761x25519-sha512@openssh.com" + ]; + + Macs = [ + "hmac-sha2-512-etm@openssh.com" + "hmac-sha2-256-etm@openssh.com" + "umac-128-etm@openssh.com" + ]; + }; + }; +} -- cgit v1.2.3