feature(gpg): move git from gpg-signing to ssh-signing
This commit is contained in:
@@ -1,6 +1,17 @@
|
||||
{ config, pkgs, inputs, ... }:
|
||||
|
||||
let
|
||||
# public half of ~/.ssh/id_ed25519, registered and verified as a signing key
|
||||
# in gitea
|
||||
signingKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHRhwzo1oxaT3fEySSmILKNnu9v30cfjx5G7FKpmfqeX aaron@argon";
|
||||
in
|
||||
{
|
||||
# gitea verifies signatures against the account key, this teaches the local
|
||||
# git the same trust so `git log --show-signature` resolves as well
|
||||
xdg.configFile."git/allowed_signers".text = ''
|
||||
aaron@0x29a.ch ${signingKey}
|
||||
'';
|
||||
|
||||
programs.git = {
|
||||
enable = true;
|
||||
settings = {
|
||||
@@ -9,9 +20,14 @@
|
||||
name = "aaron";
|
||||
email = "aaron@0x29a.ch";
|
||||
};
|
||||
gpg.ssh.allowedSignersFile = "${config.xdg.configHome}/git/allowed_signers";
|
||||
};
|
||||
signing = {
|
||||
key = "7A830180A05DAC59CDE43B0677D2F5DB48184456";
|
||||
format = "ssh";
|
||||
# point at the *public* key so ssh-keygen signs through the ssh agent
|
||||
# instead of reading the passphrase protected private key from disk
|
||||
key = "${config.home.homeDirectory}/.ssh/id_ed25519.pub";
|
||||
signer = "${pkgs.openssh}/bin/ssh-keygen";
|
||||
signByDefault = true;
|
||||
};
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user