summaryrefslogtreecommitdiff
path: root/flake.nix
diff options
context:
space:
mode:
authorDennis Kobert <dennis@kobert.dev>2026-03-10 17:05:14 +0100
committerDennis Kobert <dennis@kobert.dev>2026-03-10 17:05:14 +0100
commit334625d069b0adf9d046703daf20215bbc83bc4e (patch)
tree99d59322897f6a59d7ba32f953f33473ac86cdba /flake.nix
Initial pam-any flake with NixOS module
Diffstat (limited to 'flake.nix')
-rw-r--r--flake.nix73
1 files changed, 73 insertions, 0 deletions
diff --git a/flake.nix b/flake.nix
new file mode 100644
index 0000000..9daf707
--- /dev/null
+++ b/flake.nix
@@ -0,0 +1,73 @@
+{
+ description = "PAM module that runs multiple PAM modules in parallel, succeeding if any one succeeds";
+
+ inputs = {
+ nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
+ };
+
+ outputs = { self, nixpkgs }:
+ let
+ system = "x86_64-linux";
+ pkgs = nixpkgs.legacyPackages.${system};
+ in
+ {
+ packages.${system}.default = pkgs.callPackage ./default.nix {};
+
+ nixosModules.default = { config, pkgs, lib, ... }:
+ let
+ cfg = config.security.pam-any;
+ pam-any = self.packages.${pkgs.stdenv.hostPlatform.system}.default;
+
+ pamAnyConfig = builtins.toJSON {
+ mode = "One";
+ modules = cfg.modules;
+ };
+ in
+ {
+ options.security.pam-any = {
+ enable = lib.mkEnableOption "pam-any parallel authentication";
+
+ modules = lib.mkOption {
+ type = lib.types.attrsOf lib.types.str;
+ default = {
+ pam-any-fingerprint = "Fingerprint";
+ pam-any-password = "Password";
+ };
+ description = "Map of PAM service names to display labels for parallel auth.";
+ };
+
+ services = lib.mkOption {
+ type = lib.types.listOf lib.types.str;
+ default = [ "sudo" "login" ];
+ description = "PAM services to apply pam-any to.";
+ };
+
+ order = lib.mkOption {
+ type = lib.types.int;
+ default = 1000;
+ description = "Order of the pam-any rule in the auth stack.";
+ };
+ };
+
+ config = lib.mkIf cfg.enable {
+ security.pam.services = {
+ pam-any-fingerprint.text = ''
+ auth required ${pkgs.fprintd}/lib/security/pam_fprintd.so
+ '';
+
+ pam-any-password.text = ''
+ auth required ${pkgs.linux-pam}/lib/security/pam_unix.so
+ '';
+ } // lib.genAttrs cfg.services (_name: {
+ fprintAuth = false;
+ rules.auth.pam-any = {
+ order = cfg.order;
+ control = "sufficient";
+ modulePath = "${pam-any}/lib/security/pam_any.so";
+ args = [ pamAnyConfig ];
+ };
+ });
+ };
+ };
+ };
+}