mirror of
https://github.com/nmasur/dotfiles
synced 2026-09-08 13:36:09 +00:00
fix(ssh): use openssh.authorizedPrincipals for cloudflare certificates
This commit is contained in:
@@ -2,6 +2,12 @@
|
|||||||
|
|
||||||
## 2026-09-06
|
## 2026-09-06
|
||||||
|
|
||||||
|
- **Fixed OpenSSH authorized principals certificate authentication for Cloudflare Tunnel**:
|
||||||
|
- Replaced manual `environment.etc."ssh/authorized_principals/${username}"` symlink and `Match User` config with NixOS native `users.users.<name>.openssh.authorizedPrincipals`.
|
||||||
|
- Root cause: `environment.etc` without an explicit `mode` creates symlinks pointing into `/nix/store`, which has group-writable mode `0775` (`nixbld` group). Under `StrictModes yes`, sshd refused authentication with `bad ownership or modes for directory /nix/store`, causing certificate principal matching to fail with `Certificate does not contain an authorized principal`.
|
||||||
|
- Setting `users.users.<name>.openssh.authorizedPrincipals` causes NixOS to generate `/etc/ssh/authorized_principals.d/<name>` with `mode = "0444"`, copying the file instead of symlinking into the store, and automatically configuring `services.openssh.settings.AuthorizedPrincipalsFile = "/etc/ssh/authorized_principals.d/%u"`.
|
||||||
|
- Also added `mode = "0444"` to `/etc/ssh/ca.pub` and moved `TrustedUserCAKeys` into `services.openssh.settings`.
|
||||||
|
|
||||||
- **Configured OpenID Connect (OIDC) authentication for Mealie**:
|
- **Configured OpenID Connect (OIDC) authentication for Mealie**:
|
||||||
- Configured `services.mealie.settings` with OIDC settings pointing to Pocket ID (`auth.masu.rs`), using client ID `040925ed-b39e-4442-b8e8-369c948c0cd2`.
|
- Configured `services.mealie.settings` with OIDC settings pointing to Pocket ID (`auth.masu.rs`), using client ID `040925ed-b39e-4442-b8e8-369c948c0cd2`.
|
||||||
- Added secret management for `mealie-oidc-secret.age` via `secrets.mealie-oidc-secret`, using `prefix = "OIDC_CLIENT_SECRET="` to generate an environment file.
|
- Added secret management for `mealie-oidc-secret.age` via `secrets.mealie-oidc-secret`, using `prefix = "OIDC_CLIENT_SECRET="` to generate an environment file.
|
||||||
|
|||||||
@@ -25,7 +25,7 @@
|
|||||||
# Set ca = "<public key>"
|
# Set ca = "<public key>"
|
||||||
|
|
||||||
let
|
let
|
||||||
inherit (config.nmasur.settings) username;
|
inherit (config.nmasur.settings) username hostnames;
|
||||||
cfg = config.nmasur.presets.services.cloudflared;
|
cfg = config.nmasur.presets.services.cloudflared;
|
||||||
in
|
in
|
||||||
|
|
||||||
@@ -68,27 +68,24 @@ in
|
|||||||
|
|
||||||
# Grant Cloudflare access to SSH into this server
|
# Grant Cloudflare access to SSH into this server
|
||||||
environment.etc = {
|
environment.etc = {
|
||||||
"ssh/ca.pub".text = ''
|
"ssh/ca.pub" = {
|
||||||
${cfg.tunnel.ca}
|
text = ''
|
||||||
'';
|
${cfg.tunnel.ca}
|
||||||
|
'';
|
||||||
# Must match the username portion of the email address in Cloudflare
|
mode = "0444";
|
||||||
# Access
|
};
|
||||||
"ssh/authorized_principals".text = ''
|
|
||||||
${username}
|
|
||||||
'';
|
|
||||||
};
|
};
|
||||||
|
|
||||||
|
users.users.${username}.openssh.authorizedPrincipals = [
|
||||||
|
username
|
||||||
|
"${username}@${hostnames.mail}"
|
||||||
|
];
|
||||||
|
|
||||||
# Adjust SSH config to allow access from Cloudflare's certificate
|
# Adjust SSH config to allow access from Cloudflare's certificate
|
||||||
services.openssh.extraConfig = ''
|
services.openssh.settings = {
|
||||||
PubkeyAuthentication yes
|
TrustedUserCAKeys = "/etc/ssh/ca.pub";
|
||||||
TrustedUserCAKeys /etc/ssh/ca.pub
|
Macs = [ "hmac-sha2-512" ]; # Fix for failure to find matching mac
|
||||||
Match User '${username}'
|
};
|
||||||
AuthorizedPrincipalsFile /etc/ssh/authorized_principals
|
|
||||||
# if there is no existing AuthenticationMethods
|
|
||||||
AuthenticationMethods publickey
|
|
||||||
'';
|
|
||||||
services.openssh.settings.Macs = [ "hmac-sha2-512" ]; # Fix for failure to find matching mac
|
|
||||||
|
|
||||||
# Create credentials file for Cloudflare
|
# Create credentials file for Cloudflare
|
||||||
secrets.cloudflared = {
|
secrets.cloudflared = {
|
||||||
|
|||||||
Reference in New Issue
Block a user