From 3f3d847134ae7ae7653da538f6ba6f2874a8e847 Mon Sep 17 00:00:00 2001 From: John Lancaster <32917998+jsl12@users.noreply.github.com> Date: Thu, 2 Jul 2026 08:38:06 -0500 Subject: [PATCH] extra principals for SSH host certs --- modules/hosts/janus/default.nix | 8 ++++++++ modules/services/step-ca/ssh-host.nix | 14 ++++++++++++-- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/modules/hosts/janus/default.nix b/modules/hosts/janus/default.nix index 6173f14..3ba3553 100644 --- a/modules/hosts/janus/default.nix +++ b/modules/hosts/janus/default.nix @@ -63,6 +63,10 @@ in sops.defaultSopsFile = ../../../keys/secrets.yaml; step-ssh-host = { hostname = hostname; + extraPrincipals = [ + "192.168.1.244" + "fded:fb16:653e:25da:be24:11ff:fea0:753f" + ]; }; mtls = { enable = true; @@ -73,6 +77,10 @@ in ]; }; + # users.users."${username}".openssh.authorizedKeys.keys = [ + # "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMOkGLo4N/L3RYvaIZ1FmePlxa1HK0fMciZxKtRhN58F root@janus" + # ]; + home-manager.users."${username}" = { imports = with inputs.self.modules.homeManager; [ mysops diff --git a/modules/services/step-ca/ssh-host.nix b/modules/services/step-ca/ssh-host.nix index a189c82..df67972 100644 --- a/modules/services/step-ca/ssh-host.nix +++ b/modules/services/step-ca/ssh-host.nix @@ -5,6 +5,12 @@ provisionerPasswordPath = config.sops.secrets."janus/admin_jwk".path; sshKeyPath = "/etc/ssh/ssh_host_ed25519_key"; sshCertPath = "${sshKeyPath}-cert.pub"; + mkPrincipalArgs = principals: + lib.concatMapStringsSep " " (principal: ''--principal "${principal}"'') principals; + principalArgs = mkPrincipalArgs ([ + cfg.hostname + "${cfg.hostname}.john-stream.com" + ] ++ cfg.extraPrincipals); in { # NixOS Options @@ -18,6 +24,11 @@ type = lib.types.str; default = "admin"; }; + extraPrincipals = lib.mkOption { + description = "Additional SSH host certificate principals to include per host"; + type = with lib.types; listOf str; + default = [ ]; + }; }; imports = with inputs.self.modules.nixos; [ ssh ]; @@ -39,8 +50,7 @@ --host --sign \ --provisioner "${cfg.provisioner}" \ --provisioner-password-file "${provisionerPasswordPath}" \ - --principal "${cfg.hostname}" \ - --principal "${cfg.hostname}.john-stream.com" \ + ${principalArgs} \ "${cfg.hostname}" "${sshKeyPath}.pub" '') (writeShellScriptBin "ssh-host-cert-check" "${lib.getExe' pkgs.openssh "ssh-keygen"} -Lf ${sshCertPath}")