nixos/common: add pam-ussh

This commit is contained in:
Luke Granger-Brown 2022-06-04 12:21:32 +01:00
parent 2c6be52ce9
commit bd2be7196a

View file

@ -151,6 +151,11 @@ in
environment.homeBinInPath = true;
security.pam.enableSSHAgentAuth = true;
security.pam.ussh = {
enable = true;
control = "sufficient";
caFile = ../../secrets/client-ca.pub;
};
users.mutableUsers = false;
users.users = let secrets = depot.ops.secrets; in {