feat(nixos): enable hardware security key support (pcscd)
Some checks failed
Check / eval (push) Has been cancelled

This commit is contained in:
Bernardo Magri
2026-07-08 22:07:12 +01:00
parent eb8f9fad88
commit c6b759e19e
3 changed files with 12 additions and 7 deletions

View File

@@ -355,12 +355,6 @@ implement. Bernardo moves accepted items into a tier.*
polish. Cost: moderate — requires `hardware.i2c.enable = true`, adding
`ddcutil` to udev/groups, and building a UI path to control it.
- **[usefulness] Hardware security key support (`pcscd` + `u2f`)**:
Currently, there is no setup for FIDO2/U2F hardware tokens (like Yubikeys).
Without `services.pcscd.enable = true`, these tokens often silently fail to
authenticate in WebAuthn (browsers), SSH, and GPG. Enabling this (and
`hardware.u2f.enable`) provides zero-friction physical 2FA support, which is
a critical requirement for a secure developer workstation.
- **[usefulness] Microphone noise cancellation (`easyeffects`)**:
PipeWire is robust, but it lacks out-of-the-box noise reduction for

View File

@@ -17,6 +17,13 @@ Template:
---
## 2026-07-08 — Hardware security key support (iteration #77)
- **Task:** PROPOSED item — enable FIDO2/U2F support for hardware tokens.
- **Did:** Added `services.pcscd.enable = true` to `modules/nixos/default.nix` (NixOS >= 26.05 udev handles u2f natively).
- **Verified:** V1 (flake check).
- **Pending:** nothing.
- **Next suggestion:** continue tackling the PROPOSED backlog queue (e.g. file manager archive backend or udiskie).
## 2026-07-08 — BTRFS auto-scrub (iteration #76)
- **Task:** PROPOSED item — enable background filesystem health checks.
- **Did:** Added `services.btrfs.autoScrub` with a monthly interval to `modules/nixos/default.nix`.