Open
Description
Here are a couple of issues with the nix component of this guide:
- The
Build an air-gapped NixOS LiveCD image
part of the guide no longer works after movingflake.nix
tonix
subdirectory. Similar issue with the other commands. Adding?dir=nix
argument to the flake url should solve the problem. - The flake lock file is outdated: it contains
drduhConfig
which was removed from the flake inputs.
And other issues noticed while following it:
sudo mkdir /mnt/encrypted-storage
does not work on NixOS as/mnt
is not created by default.gpg-agent
needs to be stopped before usingykman openpgp
commands.- Transfer subkeys just doesn't work (
gpg: KEYTOCARD failed: Invalid time
error). What solved was to run the interactive command manually without--pinentry-mode=loopback
- Running
save
afterkeytocard
makes it annoying to transfer the keys to multiple yubikeys, as they are removed from gnupg. I had to delete all secret keys form my gnupg and re-import the backups.
It seems to me like the live NixOS image support is slowly being faded out. Is there a particular reason for this?
Anyways, this was a great guide, thank you to all who contributed to it!