also deploy host ca to server

This commit is contained in:
Jörg Thalheim
2024-11-14 17:52:02 +01:00
committed by kenji
parent 936a3baa08
commit 4759b9528f
2 changed files with 6 additions and 5 deletions

View File

@@ -3,9 +3,4 @@
imports = [
../shared.nix
];
programs.ssh.knownHosts.ssh-ca = lib.mkIf (config.clan.sshd.certificate.searchDomains != [ ]) {
certAuthority = true;
extraHostNames = builtins.map (domain: "*.${domain}") config.clan.sshd.certificate.searchDomains;
publicKey = config.clan.core.vars.generators.openssh-ca.files."id_ed25519.pub".value;
};
}

View File

@@ -39,5 +39,11 @@
ssh-keygen -t ed25519 -N "" -f $out/id_ed25519
'';
};
programs.ssh.knownHosts.ssh-ca = lib.mkIf (config.clan.sshd.certificate.searchDomains != [ ]) {
certAuthority = true;
extraHostNames = builtins.map (domain: "*.${domain}") config.clan.sshd.certificate.searchDomains;
publicKey = config.clan.core.vars.generators.openssh-ca.files."id_ed25519.pub".value;
};
};
}