-
-
Notifications
You must be signed in to change notification settings - Fork 15.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
nixos/duosec: replace insecure skey option with secure secretKeyFile option #78938
Conversation
34629be
to
cf0279c
Compare
4722673
to
4e1ace6
Compare
cf0279c
to
2f21158
Compare
I just noticed this is against |
2f21158
to
84f500a
Compare
@sdier I'm planning on merging this shortly. Any remaining concerns? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Sorry I've been non-responsive, my routine has been very different lately.
84f500a
to
6f0c1cd
Compare
Summary:
So merge it is. |
No problems. Thanks for circling back, I appreciate it 🎉 |
Motivation for this change
Waiting on #78902 to be merged.I tested this with the
ssh.enable
option set totrue
, though I did not test with thepam.enable
option set totrue
as I'm not clear on how that is supposed to be configured.Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)nix path-info -S
before and after)