diff options
| author | tv <tv@krebsco.de> | 2023-09-11 14:55:04 +0200 |
|---|---|---|
| committer | tv <tv@krebsco.de> | 2023-09-11 14:55:04 +0200 |
| commit | 8fc162ee3d9525a2b45346a1ca8f34ccb5ef971b (patch) | |
| tree | aa37724dd0452860d4b9b033332587c8832629e3 /lass/2configs/otp-ssh.nix | |
| parent | 90b1515dcd5b67a85cd92901fb211764b1fa5f83 (diff) | |
| parent | 083229d0211096daec08673f743ccc45b1d8a0ac (diff) | |
Merge remote-tracking branch 'orange/master'
Diffstat (limited to 'lass/2configs/otp-ssh.nix')
| -rw-r--r-- | lass/2configs/otp-ssh.nix | 18 |
1 files changed, 0 insertions, 18 deletions
diff --git a/lass/2configs/otp-ssh.nix b/lass/2configs/otp-ssh.nix deleted file mode 100644 index f9984e245..000000000 --- a/lass/2configs/otp-ssh.nix +++ /dev/null @@ -1,18 +0,0 @@ -{ pkgs, ... }: -# Enables second factor for ssh password login - -## Usage: -# gen-oath-safe <username> totp -## scan the qrcode with google authenticator (or FreeOTP) -## copy last line into secrets/<host>/users.oath (chmod 700) -{ - security.pam.oath = { - # enabling it will make it a requisite of `all` services - # enable = true; - digits = 6; - # TODO assert existing - usersFile = (toString <secrets>) + "/users.oath"; - }; - # I want TFA only active for sshd with password-auth - security.pam.services.sshd.oathAuth = true; -} |
