From 4ff7edff0db1a4382519d8907d96dfc60a8e8df3 Mon Sep 17 00:00:00 2001 From: chn Date: Thu, 29 Jun 2023 22:03:24 +0800 Subject: [PATCH] add more u2f auth --- modules/basic.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/modules/basic.nix b/modules/basic.nix index 42dad097..424ef9a4 100644 --- a/modules/basic.nix +++ b/modules/basic.nix @@ -41,7 +41,8 @@ security.pam = { u2f = { enable = true; cue = true; authFile = inputs.config.sops.secrets."u2f".path; }; - services = { login.u2fAuth = true; sudo.u2fAuth = true; }; + services = builtins.listToAttrs (builtins.map (name: { inherit name; value = { u2fAuth = true; }; }) + [ "login" "sudo" "su" "kde" "polkit-1" ]); }; sops.secrets.u2f.neededForUsers = true; systemd.nspawn.arch =