diff options
-rw-r--r-- | nixos/secrets/secrets.nix | 3 | ||||
-rw-r--r-- | nixos/secrets/vpn-se-presharedKey.age | 14 | ||||
-rw-r--r-- | nixos/secrets/vpn-se-privKey.age | 21 | ||||
-rw-r--r-- | nixos/shared/vpn.nix | 8 |
4 files changed, 15 insertions, 31 deletions
diff --git a/nixos/secrets/secrets.nix b/nixos/secrets/secrets.nix index db19967..6021803 100644 --- a/nixos/secrets/secrets.nix +++ b/nixos/secrets/secrets.nix @@ -1,10 +1,9 @@ let - martin = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICRBAAt77GXrDtIp6fSjeMHCV3e1ujCE0meetqX3YZpn"; + martin = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF+moAzcnDJsyUalRVdLeJS1D5wezwMDyHuM+Cyk1nQh"; hamac = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJmjbC0gk2s/qDQ+QR//GJH0ZPld99L0EtX7dPP5h2RN"; ev = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINCSypbTOnAYBO32vUUieOsb6ws32gCsDg8nB8JhuFuI"; in { "vpn-se-privKey.age".publicKeys = [ martin hamac ev ]; - "vpn-se-presharedKey.age".publicKeys = [ martin hamac ev ]; } diff --git a/nixos/secrets/vpn-se-presharedKey.age b/nixos/secrets/vpn-se-presharedKey.age deleted file mode 100644 index 1f56d86..0000000 --- a/nixos/secrets/vpn-se-presharedKey.age +++ /dev/null @@ -1,14 +0,0 @@ -age-encryption.org/v1 --> ssh-ed25519 0iFcGg 33qVwdJ+x5d9ezpvYayjZqrwAZQDb7AxvOjQucyVYgQ -z5/tRvXEE+xSJ4BKQORu4yI+UG2GNaKdTZe0FkN4VyY --> ssh-ed25519 zNg/mg 9rug5AzVUH/fIDvtSVA0SZkQ0tR+T59VY2UYPrxZfFM -g49jKdkf+tz/sl9g/RdfkRv/CKneO04rkXPprQYv9rw --> ssh-ed25519 PHC5tQ H9j903SKpztlrUN/nP7Q8Io/iJLY8ka6aBlOc4d/+iA -hfQIpLuvT2D8eo5T0MmydivcQE7DFbHhLO809YET0HI --> W}8>=-grease -hy4mn+TGe6QPbZud+cppGmgzyed8SgVcaYBumJdxIRy6NQXW8PH2itg6GTIR6Npb -Nhj9zeSsQvAq8no7z+Q5DsXI7o6iVUDgvoQ1HcUan7WYGqR5MA0 ---- WbaGYSFVrJ8+YgzYeLaLXfOsCDMMruUpmFtKvtym57E -Ik"a#L!1\: -=.+$@].Hnd]U/q-~-T -
\ No newline at end of file diff --git a/nixos/secrets/vpn-se-privKey.age b/nixos/secrets/vpn-se-privKey.age index 93de475..ca2a8eb 100644 --- a/nixos/secrets/vpn-se-privKey.age +++ b/nixos/secrets/vpn-se-privKey.age @@ -1,11 +1,12 @@ age-encryption.org/v1 --> ssh-ed25519 0iFcGg KyKfFePFWpX9AOPw5Sy9UQkucPsQDwrEwRL66e3wdA4 -7DNSkNroD1HaRld0M5uMWtu7dojKUB7DPU9hdTPCXZ8 --> ssh-ed25519 zNg/mg Y0w7MCgwQKqb8FurFOyEshSmfCNoIKi0OnOJUsDeh14 -xILssj5y6XbZ10b39MqqhN42DRQt1AKIdh/Eidin8dA --> ssh-ed25519 PHC5tQ nfW6lDN4vrv5EOCZGmfe9LEto5FDbU9Vh1LOvrnpvR0 -KrGBpZh7+DalPFoM0rW6ylehDnrmCz2JAOKqMEN4BoQ --> k4]AeAV-grease pSemvkw @C;y -vBW8ETA ---- 8Eel9tqXmZ3s7J1CqXlCMTOPAHWD/ftxB7t2DRtHi4A -T{vgmWe 5Yxr嶘v} ]MCMbHAZ?\Hl'L,
\ No newline at end of file +-> ssh-ed25519 PMTW+A WNGr/0aVmRRmhZ6P6PaWxPML3VRBi59QTD5kQ2AuqXk +6ivhC1Cm/DVWdCxx+48U0YzJqhj0rmZ195SmjEX+Y4k +-> ssh-ed25519 zNg/mg I4MbADHlAgwced5uYaEWXNgKvzfyGxKAWiXtg7rgRCg +ipQGQn7rCu59gHq5DjQIckvqGO5P/LJTtSP8yViEVdQ +-> ssh-ed25519 PHC5tQ xsy2ivym+ymHacFJeTwll7aJyypoQTg8h/DyaVp98xs +rwPb2fCAtHKzUQgZ/0SxKZ37MnVb8u74vesd0o5G7yc +-> @n>>$-grease @J3N{1sN qN_Oh]I K(# +dA +--- P0ZI10bTAqn+OPH84hF1V+Qa/X7gqvMZHkYAZQg5zgo +v:LՓQ "[YU +KY?+$Aa?`o[k369U0Ȯ8PH[H*g`w
\ No newline at end of file diff --git a/nixos/shared/vpn.nix b/nixos/shared/vpn.nix index 59fb225..9cbcf45 100644 --- a/nixos/shared/vpn.nix +++ b/nixos/shared/vpn.nix @@ -2,7 +2,6 @@ { age.secrets.vpn-se-privKey.file = ../secrets/vpn-se-privKey.age; - age.secrets.vpn-se-presharedKey.file = ../secrets/vpn-se-presharedKey.age; # We're creating the wireguard interfaces in network namespaces so that # we can use them on demand: @@ -14,15 +13,14 @@ interfaces.wg-se = { interfaceNamespace = "se"; - ips = ["10.148.171.71/32"]; + ips = ["10.128.241.130/32"]; privateKeyFile = config.age.secrets.vpn-se-privKey.path; peers = [ { - publicKey = "PyLCXAQT8KkM4T+dUsOQfn+Ub3pGxfGlxkIApuig+hk="; - presharedKeyFile = config.age.secrets.vpn-se-presharedKey.path; + publicKey = "sb61ho9MhaxhJd6WSrryVmknq0r6oHEW7PP5i4lzAgM="; allowedIPs = ["0.0.0.0/0"]; - endpoint = "se3.vpn.airdns.org:1637"; + endpoint = "se.gw.xeovo.com:51820"; } ]; }; |