diff options
| author | Kleidi Bujari <mail@4kb.net> | 2025-04-02 22:11:38 -0400 |
|---|---|---|
| committer | Kleidi Bujari <mail@4kb.net> | 2025-04-02 22:11:38 -0400 |
| commit | c950f338c5720a132552863a35d1c7924df3d3a6 (patch) | |
| tree | c3134c42e1618c255ca8e9e0698f90b0ae8b3563 /machines/xnet/net/sshd.nix | |
| parent | b619ff9dd42eaa62569c8297142f0e4c719d40d2 (diff) | |
| parent | 09c2b6de63a6ff35348fcb2c2eb57b974f0a8a52 (diff) | |
| download | depot-c950f338c5720a132552863a35d1c7924df3d3a6.tar.gz depot-c950f338c5720a132552863a35d1c7924df3d3a6.tar.bz2 depot-c950f338c5720a132552863a35d1c7924df3d3a6.zip | |
Merge remote-tracking branch 'origin/copy-blueprint'
Diffstat (limited to 'machines/xnet/net/sshd.nix')
| -rw-r--r-- | machines/xnet/net/sshd.nix | 46 |
1 files changed, 0 insertions, 46 deletions
diff --git a/machines/xnet/net/sshd.nix b/machines/xnet/net/sshd.nix deleted file mode 100644 index 9d7976e..0000000 --- a/machines/xnet/net/sshd.nix +++ /dev/null @@ -1,46 +0,0 @@ -{ config, lib, ... }: -let - cfg = config.xnet.net.sshd; - inherit (lib) mkOption mkIf types; -in -{ - options.xnet.net.sshd = { - enable = mkOption { - type = types.bool; - default = false; - description = "Enable hardened SSH service."; - }; - }; - - config = mkIf cfg.enable { - services.openssh = { - enable = true; - startWhenNeeded = true; - openFirewall = true; - hostKeys = [{ - path = "/persist/certs/ssh/ssh_host_ed25519_key"; - type = "ed25519"; - }]; - settings = { - UsePAM = false; - X11Forwarding = false; - PermitRootLogin = "prohibit-password"; - PasswordAuthentication = false; - Ciphers = [ "chacha20-poly1305@openssh.com" ]; - Macs = [ "hmac-sha2-512-etm@openssh.com" ]; - KexAlgorithms = [ "curve25519-sha256@libssh.org" ]; - }; - sftpServerExecutable = "internal-sftp"; - sftpFlags = [ "-f AUTHPRIV" "-l INFO" ]; - extraConfig = - let - pubkeyTypes = lib.strings.concatStringsSep "," [ - "sk-ssh-ed25519-cert-v01@openssh.com" - "ssh-ed25519-cert-v01@openssh.com" - "ssh-ed25519" - ]; - in - "PubkeyAcceptedKeyTypes ${pubkeyTypes}"; - }; - }; -} |
