1 { lib, pkgs, config, mylibs, myconfig, ... }:
4 networking.firewall.allowedTCPPorts = [ 22 ];
6 services.openssh.extraConfig = ''
7 AuthorizedKeysCommand /etc/ssh/ldap_authorized_keys
8 AuthorizedKeysCommandUser nobody
11 environment.etc."ssh/ldap_authorized_keys" = let
12 ldap_authorized_keys =
14 name = "ldap_authorized_keys";
15 file = ./ldap_authorized_keys.sh;
17 LDAP_PASS = myconfig.env.sshd.ldap.password;
18 GITOLITE_SHELL = "${pkgs.gitolite}/bin/gitolite-shell";
19 ECHO = "${pkgs.coreutils}/bin/echo";
21 paths = [ pkgs.openldap pkgs.stdenv.shellPackage pkgs.gnugrep pkgs.gnused pkgs.coreutils ];
27 source = ldap_authorized_keys;