rekey secrets to include recovery key
This commit is contained in:
parent
dbf2b648c9
commit
464e24d011
Binary file not shown.
Binary file not shown.
|
@ -19,18 +19,18 @@ let
|
||||||
|
|
||||||
all = [ alpha omega tor recovery ];
|
all = [ alpha omega tor recovery ];
|
||||||
in
|
in
|
||||||
{
|
builtins.mapAttrs (name: value: { publicKeys = value ++ [ recovery ]; }) {
|
||||||
"users-hashed-password-file.age".publicKeys = all;
|
"users-hashed-password-file.age" = all;
|
||||||
|
|
||||||
# Secret network addresses
|
# Secret network addresses
|
||||||
"netdev-51-wg-sigma-p2p-address.age".publicKeys = [ alpha ];
|
"netdev-51-wg-sigma-p2p-address.age" = [ alpha ];
|
||||||
"network-wg-sigma-p2p-address.age".publicKeys = [ omega ];
|
"network-wg-sigma-p2p-address.age" = [ omega ];
|
||||||
|
|
||||||
## Wireguard
|
## Wireguard
|
||||||
# The preshared key adds an additional layer of symmetric-key crypto to be
|
# The preshared key adds an additional layer of symmetric-key crypto to be
|
||||||
# mixed into the already existing public-key crypto, for post-quantum
|
# mixed into the already existing public-key crypto, for post-quantum
|
||||||
# resistance. Public-keys are generated using `wireguard-vanity-address`.
|
# resistance. Public-keys are generated using `wireguard-vanity-address`.
|
||||||
"wireguard-preshared-key-file.age".publicKeys = [ alpha omega ];
|
"wireguard-preshared-key-file.age" = [ alpha omega ];
|
||||||
"wireguard-private-key-file-alpha.age".publicKeys = [ alpha ];
|
"wireguard-private-key-file-alpha.age" = [ alpha ];
|
||||||
"wireguard-private-key-file-omega.age".publicKeys = [ omega ];
|
"wireguard-private-key-file-omega.age" = [ omega ];
|
||||||
}
|
}
|
||||||
|
|
Binary file not shown.
|
@ -1,8 +1,9 @@
|
||||||
age-encryption.org/v1
|
age-encryption.org/v1
|
||||||
-> ssh-ed25519 KjvmEQ u+aOAxwH7BgSou88oBlAFTsLZ+Wmbr5ld99nEeBfoic
|
-> ssh-ed25519 KjvmEQ QVI3KB2XSIhimn+3nTkS0Hr/DPKtCOcfHFSp7/QLAXk
|
||||||
TiJ7uXPXDcZ6GZCErXk+VbTSlX0ECDtYg0175DX4+LI
|
tD1fdY3ii08ZqTDEPvYzydFqiok5y4zrnp+GQekz5wg
|
||||||
-> ssh-ed25519 fY+XUg KKDaoOcbkTSgsYQ7KEkP507tjoAin2jgoQ7bJDD7lh8
|
-> ssh-ed25519 fY+XUg hJmzN3gINK23Rw1qCd3KJjwPvVvfRZx9VEfDTPRWn2o
|
||||||
QTkdXdVK5PN36YglJ2nJKTh5S1Fwy3Myd8kURBPZIcY
|
H3rEhjp11wPEQFgg1hXFZwl2ZfecIIx4yxQ/w90YpdA
|
||||||
--- vcBtZKjPxYnScGb2tizt/USndbXTQcOLorikniOUVbA
|
-> X25519 hjuZ3YjV9Gf7LHwjzKXRyXC1YGJVZMw3ochzecB9Smw
|
||||||
£ýàº@ÇÒû=–)ÄÁð"xj°P
|
oDpsj16YtEoXa+63jVYc3ZyhGFvSebZ/a/YbGLAig80
|
||||||
ªëß+7)YÑÉ|¾
<>Þú‹ ý~×Íi³½g"ªãilEþ¤‡¼U²ÀÃyî{•ÀBa)
|
--- uZOOPTTyS3p61t7R89nzO/hy4mrHTOoEaM/A0Nmz030
|
||||||
|
ÞýtºK»¾óÌ4w¡˜Á7´Q'×Užûß’òä‹4N^cñÌToÃï³\xIyíxt)œÆO}$L<1D>*h$¦Uê„ÁªþÞÂq…£õP
|
Binary file not shown.
Binary file not shown.
Loading…
Reference in a new issue