diff --git a/home/alex/ssh.nix b/home/alex/ssh.nix new file mode 100644 index 0000000..3bf73a5 --- /dev/null +++ b/home/alex/ssh.nix @@ -0,0 +1,15 @@ +{ ... }: + +{ + programs.ssh = { + enable = true; + + matchBlocks = { + "github.com" = { + hostname = "github.com"; + user = "git"; + identityFile = "~/.ssh/id_github"; + }; + }; + }; +} diff --git a/justfile b/justfile index fa183a8..aa2d1d3 100644 --- a/justfile +++ b/justfile @@ -1,4 +1,5 @@ host := `hostname` +key_services := "github gradescope" rebuild: sudo nixos-rebuild switch --flake .#{{host}} @@ -10,3 +11,20 @@ gc: sudo nix-env --delete-generations +3 sudo nix-store --gc +# Generate high-strength, post-quantum ready SSH keys without passphrases +gen-keys: + #!/usr/bin/env bash + set -euo pipefail + mkdir -p ~/.ssh + + for service in {{key_services}}; do + FILE="$HOME/.ssh/id_$service" + + if [ -f "$FILE" ]; then + echo "skipping: $FILE already exists." + else + echo "generating: $FILE" + ssh-keygen -t ed25519 -a 100 -o -f "$FILE" -N "" + fi + done +