WIP: easy hm gpg setup without sudo

This commit is contained in:
Gabriel Fontes
2022-08-19 21:55:15 +00:00
parent 304b0a39e1
commit 04b2f46191
3 changed files with 39 additions and 33 deletions
+2
View File
@@ -97,6 +97,8 @@
enable = true;
initExtra = lib.mkAfter ''
exec ${config.programs.fish.package}/bin/fish
# Make sure GPG SSH works
export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)
'';
};
}
+36 -32
View File
@@ -23,41 +23,45 @@ in
enableExtraSocket = true;
};
programs = {
# Start gpg-agent if it's not running or tunneled in
# SSH does not start it automatically, so this is needed to avoid having to use a gpg command at startup
# https://www.gnupg.org/faq/whats-new-in-2.1.html#autostart
bash.profileExtra = "gpgconf --launch gpg-agent";
fish.loginShellInit = "gpgconf --launch gpg-agent";
zsh.loginExtra = "gpgconf --launch gpg-agent";
};
programs =
let
fixGpg = ''
gpgconf --launch gpg-agent
export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)
''; in
{
# Start gpg-agent if it's not running or tunneled in
# SSH does not start it automatically, so this is needed to avoid having to use a gpg command at startup
# https://www.gnupg.org/faq/whats-new-in-2.1.html#autostart
bash.profileExtra = fixGpg;
fish.loginShellInit = fixGpg;
zsh.loginExtra = fixGpg;
gpg = {
enable = true;
settings = {
trust-model = "tofu+pgp";
};
publicKeys = [
{
source = fetchKey {
url = "https://misterio.me/7088C7421873E0DB97FF17C2245CAB70B4C225E9.asc";
sha256 = "sha256:1bck1r1dfg10za5y9nj7yshr6k69g0lypqp5fjs21d5s68za1rmb";
};
trust = 5;
}
{
source = fetchKey {
url = "https://guip.dev/43827E2886E5C34F38D577538C814D625FBD99D1.asc";
sha256 = "sha256:1r5lxq4xrqjz8c16l6yh10ablgqrqssgsgshpfaphnfqp6hhvvjd";
};
trust = 4;
}
];
};
};
home.persistence = lib.mkIf persistence {
"/persist/home/misterio".directories = [ ".gnupg" ];
};
programs.gpg = {
enable = true;
settings = {
trust-model = "tofu+pgp";
};
publicKeys = [
{
source = fetchKey {
url = "https://misterio.me/7088C7421873E0DB97FF17C2245CAB70B4C225E9.asc";
sha256 = "sha256:1bck1r1dfg10za5y9nj7yshr6k69g0lypqp5fjs21d5s68za1rmb";
};
trust = 5;
}
{
source = fetchKey {
url = "https://guip.dev/43827E2886E5C34F38D577538C814D625FBD99D1.asc";
sha256 = "sha256:1r5lxq4xrqjz8c16l6yh10ablgqrqssgsgshpfaphnfqp6hhvvjd";
};
trust = 4;
}
];
};
}
# vim: filetype=nix
+1 -1
View File
@@ -7,7 +7,7 @@ in
programs.ssh = {
enable = true;
matchBlocks.home = {
host = builtins.concatStringsSep " " hostnames;
host = builtins.concatStringsSep " " (hostnames ++ [ "*.misterio.me" "*.fontes.dev.br" ]);
forwardAgent = true;
remoteForwards = [{
bind.address = ''/run/user/1000/gnupg/S.gpg-agent'';