2023-06-19 01:36:50 -04:00
|
|
|
{
|
2023-11-22 15:33:16 -05:00
|
|
|
pkgs,
|
|
|
|
lib,
|
2023-12-01 16:53:51 -05:00
|
|
|
config,
|
2023-11-22 15:33:16 -05:00
|
|
|
...
|
2023-12-01 16:53:51 -05:00
|
|
|
}: let
|
|
|
|
grosshack = config.customPkgs.pam-fprint-grosshack;
|
|
|
|
grosshackSo = "${grosshack}/lib/security/pam_fprintd_grosshack.so";
|
|
|
|
gnomeSo = "${pkgs.gnome.gnome-keyring}/lib/security/pam_gnome_keyring.so";
|
|
|
|
in {
|
2023-06-19 01:36:50 -04:00
|
|
|
services.fprintd.enable = true;
|
|
|
|
|
2023-06-20 15:24:07 -04:00
|
|
|
# https://www.reddit.com/r/NixOS/comments/z7i83r/fingertip_tip_start_fprintd_at_boot_for_a_quick/
|
2023-06-19 01:36:50 -04:00
|
|
|
systemd.services.fprintd = {
|
2023-11-22 15:33:16 -05:00
|
|
|
wantedBy = ["multi-user.target"];
|
2023-06-19 01:36:50 -04:00
|
|
|
serviceConfig.Type = "simple";
|
|
|
|
};
|
|
|
|
|
|
|
|
services.logind.lidSwitch = "lock";
|
|
|
|
|
|
|
|
security.sudo.extraConfig = ''
|
2023-08-09 22:09:48 -04:00
|
|
|
Defaults timestamp_timeout=600
|
2023-06-19 01:36:50 -04:00
|
|
|
'';
|
|
|
|
|
|
|
|
security.pam.services = {
|
|
|
|
# all the changes in /etc/pam.d/*
|
2023-11-22 15:33:16 -05:00
|
|
|
sddm.text = lib.mkBefore ''
|
2023-06-19 01:36:50 -04:00
|
|
|
auth [success=1 new_authtok_reqd=1 default=ignore] pam_unix.so try_first_pass likeauth nullok
|
2023-07-15 17:47:37 -04:00
|
|
|
auth sufficient ${pkgs.fprintd}/lib/security/pam_fprintd.so
|
2023-06-19 01:36:50 -04:00
|
|
|
'';
|
|
|
|
|
|
|
|
sudo.text = ''
|
|
|
|
# Account management.
|
2023-12-01 16:53:51 -05:00
|
|
|
auth sufficient ${grosshackSo}
|
2023-06-19 01:36:50 -04:00
|
|
|
auth sufficient pam_unix.so try_first_pass nullok
|
|
|
|
account required pam_unix.so
|
|
|
|
|
|
|
|
# Authentication management.
|
|
|
|
auth required pam_deny.so
|
|
|
|
|
|
|
|
# Password management.
|
|
|
|
password sufficient pam_unix.so nullok yescrypt
|
|
|
|
|
|
|
|
# Session management.
|
|
|
|
session required pam_env.so conffile=/etc/pam/environment readenv=0
|
|
|
|
session required pam_unix.so
|
|
|
|
'';
|
|
|
|
|
|
|
|
login.text = ''
|
|
|
|
# Account management.
|
|
|
|
account required pam_unix.so
|
|
|
|
|
|
|
|
# Authentication management.
|
2023-12-01 16:53:51 -05:00
|
|
|
auth sufficient ${grosshackSo}
|
2023-06-19 01:36:50 -04:00
|
|
|
auth optional pam_unix.so nullok likeauth
|
2023-12-01 16:53:51 -05:00
|
|
|
auth optional ${gnomeSo}
|
2023-06-19 01:36:50 -04:00
|
|
|
auth sufficient pam_unix.so try_first_pass nullok
|
|
|
|
auth required pam_deny.so
|
|
|
|
|
|
|
|
# Password management.
|
|
|
|
password sufficient pam_unix.so nullok yescrypt
|
2023-12-01 16:53:51 -05:00
|
|
|
password optional ${gnomeSo} use_authtok
|
2023-06-19 01:36:50 -04:00
|
|
|
|
|
|
|
# Session management.
|
|
|
|
session required pam_env.so conffile=/etc/pam/environment readenv=0
|
|
|
|
session required pam_unix.so
|
|
|
|
session required pam_loginuid.so
|
2023-07-15 17:47:37 -04:00
|
|
|
session required ${pkgs.pam}/lib/security/pam_lastlog.so silent
|
|
|
|
session optional ${pkgs.systemd}/lib/security/pam_systemd.so
|
2023-12-01 16:53:51 -05:00
|
|
|
session optional ${gnomeSo} auto_start
|
2023-06-19 01:36:50 -04:00
|
|
|
'';
|
|
|
|
|
|
|
|
polkit-1.text = ''
|
|
|
|
# Account management.
|
|
|
|
account required pam_unix.so
|
|
|
|
|
|
|
|
# Authentication management.
|
2023-12-01 16:53:51 -05:00
|
|
|
auth sufficient ${grosshackSo}
|
2023-06-19 01:36:50 -04:00
|
|
|
auth sufficient pam_unix.so try_first_pass nullok
|
|
|
|
auth required pam_deny.so
|
|
|
|
|
|
|
|
# Password management.
|
|
|
|
password sufficient pam_unix.so nullok yescrypt
|
|
|
|
|
|
|
|
# Session management.
|
|
|
|
session required pam_env.so conffile=/etc/pam/environment readenv=0
|
|
|
|
session required pam_unix.so
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
}
|