diff options
| author | Kleidi Bujari <mail@4kb.net> | 2025-04-02 21:59:20 -0400 |
|---|---|---|
| committer | Kleidi Bujari <mail@4kb.net> | 2025-04-02 21:59:20 -0400 |
| commit | 09c2b6de63a6ff35348fcb2c2eb57b974f0a8a52 (patch) | |
| tree | bd8f1d3a51f12cd98764ae572b00f0b32de62644 /modules/xnet/net/sshd.nix | |
| parent | b1738c105de3bc0ba7cd27f68c9eb146439a0964 (diff) | |
| download | depot-09c2b6de63a6ff35348fcb2c2eb57b974f0a8a52.tar.gz depot-09c2b6de63a6ff35348fcb2c2eb57b974f0a8a52.tar.bz2 depot-09c2b6de63a6ff35348fcb2c2eb57b974f0a8a52.zip | |
automate project structure
Diffstat (limited to 'modules/xnet/net/sshd.nix')
| -rw-r--r-- | modules/xnet/net/sshd.nix | 46 |
1 files changed, 46 insertions, 0 deletions
diff --git a/modules/xnet/net/sshd.nix b/modules/xnet/net/sshd.nix new file mode 100644 index 0000000..9d7976e --- /dev/null +++ b/modules/xnet/net/sshd.nix @@ -0,0 +1,46 @@ +{ config, lib, ... }: +let + cfg = config.xnet.net.sshd; + inherit (lib) mkOption mkIf types; +in +{ + options.xnet.net.sshd = { + enable = mkOption { + type = types.bool; + default = false; + description = "Enable hardened SSH service."; + }; + }; + + config = mkIf cfg.enable { + services.openssh = { + enable = true; + startWhenNeeded = true; + openFirewall = true; + hostKeys = [{ + path = "/persist/certs/ssh/ssh_host_ed25519_key"; + type = "ed25519"; + }]; + settings = { + UsePAM = false; + X11Forwarding = false; + PermitRootLogin = "prohibit-password"; + PasswordAuthentication = false; + Ciphers = [ "chacha20-poly1305@openssh.com" ]; + Macs = [ "hmac-sha2-512-etm@openssh.com" ]; + KexAlgorithms = [ "curve25519-sha256@libssh.org" ]; + }; + sftpServerExecutable = "internal-sftp"; + sftpFlags = [ "-f AUTHPRIV" "-l INFO" ]; + extraConfig = + let + pubkeyTypes = lib.strings.concatStringsSep "," [ + "sk-ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519" + ]; + in + "PubkeyAcceptedKeyTypes ${pubkeyTypes}"; + }; + }; +} |
