Here are a couple of issues with the nix component of this guide:
- The
Build an air-gapped NixOS LiveCD image part of the guide no longer works after moving flake.nix to nix subdirectory. Similar issue with the other commands. Adding ?dir=nix argument to the flake url should solve the problem.
- The flake lock file is outdated: it contains
drduhConfig which was removed from the flake inputs.
And other issues noticed while following it:
sudo mkdir /mnt/encrypted-storage does not work on NixOS as /mnt is not created by default.
gpg-agent needs to be stopped before using ykman openpgp commands.
- Transfer subkeys just doesn't work (
gpg: KEYTOCARD failed: Invalid time error). What solved was to run the interactive command manually without --pinentry-mode=loopback
- Running
save after keytocard makes it annoying to transfer the keys to multiple yubikeys, as they are removed from gnupg. I had to delete all secret keys form my gnupg and re-import the backups.
It seems to me like the live NixOS image support is slowly being faded out. Is there a particular reason for this?
Anyways, this was a great guide, thank you to all who contributed to it!
Here are a couple of issues with the nix component of this guide:
Build an air-gapped NixOS LiveCD imagepart of the guide no longer works after movingflake.nixtonixsubdirectory. Similar issue with the other commands. Adding?dir=nixargument to the flake url should solve the problem.drduhConfigwhich was removed from the flake inputs.And other issues noticed while following it:
sudo mkdir /mnt/encrypted-storagedoes not work on NixOS as/mntis not created by default.gpg-agentneeds to be stopped before usingykman openpgpcommands.gpg: KEYTOCARD failed: Invalid timeerror). What solved was to run the interactive command manually without--pinentry-mode=loopbacksaveafterkeytocardmakes it annoying to transfer the keys to multiple yubikeys, as they are removed from gnupg. I had to delete all secret keys form my gnupg and re-import the backups.It seems to me like the live NixOS image support is slowly being faded out. Is there a particular reason for this?
Anyways, this was a great guide, thank you to all who contributed to it!