caesium: accounts and yubikey
This commit is contained in:
@@ -0,0 +1,43 @@
|
||||
# YubiKey (FIDO2/U2F) login via pam_u2f.
|
||||
#
|
||||
# `security.pam.u2f.enable = true` defaults every PAM service's `u2fAuth` to
|
||||
# true, so this covers sudo, sddm/sddm-greeter, the Plasma lock screen (the
|
||||
# `kde` service, added by services.desktopManager.plasma6), login, and su
|
||||
# without listing them individually. `control = "sufficient"` means a touch
|
||||
# skips the password, but the password always still works — losing both
|
||||
# enrolled keys can never lock this account out.
|
||||
#
|
||||
# /etc/u2f_mappings starts empty. Enroll keys after the first switch with the
|
||||
# `yubikey-enroll` / `yubikey-unenroll` scripts (defined in caesium.home.nix),
|
||||
# which wrap the interactive pamu2fcfg touch ceremony and keep
|
||||
# yubikey.u2f-mappings well-formed; then re-run nix-update. An empty/missing
|
||||
# mapping just falls through to the password, so this is safe to deploy
|
||||
# before enrollment.
|
||||
{ pkgs, ... }:
|
||||
|
||||
{
|
||||
services.pcscd.enable = true;
|
||||
services.udev.packages = [
|
||||
pkgs.yubikey-personalization
|
||||
pkgs.libfido2
|
||||
];
|
||||
|
||||
security.pam.u2f = {
|
||||
enable = true;
|
||||
control = "sufficient";
|
||||
settings = {
|
||||
cue = true;
|
||||
authfile = "/etc/u2f_mappings";
|
||||
origin = "pam://mbessette";
|
||||
appid = "pam://mbessette";
|
||||
};
|
||||
};
|
||||
|
||||
environment.etc."u2f_mappings".source = ./yubikey.u2f-mappings;
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
pam_u2f
|
||||
yubikey-manager
|
||||
libfido2
|
||||
];
|
||||
}
|
||||
Reference in New Issue
Block a user