Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

agenix-pass a pass compliant #15

Closed
blaggacao opened this issue Dec 29, 2020 · 6 comments
Closed

agenix-pass a pass compliant #15

blaggacao opened this issue Dec 29, 2020 · 6 comments

Comments

@blaggacao
Copy link
Contributor

blaggacao commented Dec 29, 2020

For a more unified, devops-dream, future-proof secrets management.

divnix/digga#56

There is the advent of (cheap, as in here-implementation / here-maintenance) FIDO2 integration on the horizon: https://github.com/str4d/age-plugin-yubikey — specifically: str4d/age-plugin-yubikey#1

@ryantm
Copy link
Owner

ryantm commented May 13, 2021

I don't understand what this is asking for @blaggacao. It seems to be talking about yubikey and pass. What do you want to store in pass?

@blaggacao
Copy link
Contributor Author

blaggacao commented May 13, 2021

Thank you for asking. As far as I can remember, this was part of a research stride.

That stride has been driven by a vision to manage pass secrets as part of the nixos host (or home) state via age (instead of gpg). Agenix, in that idea, would provide the api and implementation of how secrets would be stored with a pass-compatible.

The specific link represents a relatively cheap way to unlock any age encrypted secret with a FIDO2 device: an enabler for any age(nix) based pass-compatible.

Since then, there seems to be a specification coming around: https://hackmd.io/@str4d/age-plugin-yubikey

To this end, I'd guess this issue asked for acknowledgment of age-plugin-yubikey, and a general feedback on the (abstract) idea of an agenix-pass. (If that makes sense)

@asymmetric
Copy link
Contributor

There's preliminary support for rage plugins, one of which is for Yubikeys. Until that lands more properly, I don't think there's much to do on agenix's side though.

@blaggacao
Copy link
Contributor Author

Should we close this? This is not going to be immediatly actionable. I think we are still a few upstream iterations away for crafting well-integrated nixos specific solutions for pass' state.

@ryantm ryantm closed this as completed May 15, 2021
@blaggacao
Copy link
Contributor Author

For what it's worth, word is spreading that the state of the age ecosystem might slowly have reached a state where this can be attempted upon.

@pinpox
Copy link

pinpox commented Mar 24, 2022

Any updates on the yubikey support?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants