diff options
| author | Kleidi Bujari <mail@4kb.net> | 2024-12-01 22:30:26 -0500 |
|---|---|---|
| committer | Kleidi Bujari <mail@4kb.net> | 2024-12-01 22:30:26 -0500 |
| commit | f08f3812f40322b6098d75573413ed83f358871f (patch) | |
| tree | 0f864c4695dab404e261e6bf179cfc1b04d6c7f5 /modules/xnet/net/sshd.nix | |
| parent | 3ccc7e784a0ed5b19910ab856f6d9774a6f27956 (diff) | |
| download | depot-f08f3812f40322b6098d75573413ed83f358871f.tar.gz depot-f08f3812f40322b6098d75573413ed83f358871f.tar.bz2 depot-f08f3812f40322b6098d75573413ed83f358871f.zip | |
Cleanup xnet module and add baseline modules
With these changes, the xnet module is useable as a system builder. At
this point, it is still undecided whether all configuration will be
generalized into this module, rather than keeping mini-modules local to
the machine they will run on.
Diffstat (limited to 'modules/xnet/net/sshd.nix')
| -rw-r--r-- | modules/xnet/net/sshd.nix | 46 |
1 files changed, 46 insertions, 0 deletions
diff --git a/modules/xnet/net/sshd.nix b/modules/xnet/net/sshd.nix new file mode 100644 index 0000000..ef225db --- /dev/null +++ b/modules/xnet/net/sshd.nix @@ -0,0 +1,46 @@ +{ config, lib, ... }: +let + cfg = config.xnet.net.sshd; + inherit (lib) mkOption mkIf types; +in +{ + options.xnet.net.sshd = { + enable = mkOption { + type = types.bool; + default = false; + description = "Enable hardened SSH service."; + }; + }; + + config = mkIf cfg.enable { + services.openssh = { + enable = true; + startWhenNeeded = true; + openFirewall = true; + hostKeys = [{ + path = "/persist/certs/ssh/ssh_host_ed25519_key"; + type = "ed25519"; + }]; + settings = { + UsePAM = true; + X11Forwarding = false; + PermitRootLogin = "no"; + PasswordAuthentication = false; + Ciphers = [ "chacha20-poly1305@openssh.com" ]; + Macs = [ "hmac-sha2-512-etm@openssh.com" ]; + KexAlgorithms = [ "curve25519-sha256@libssh.org" ]; + }; + sftpServerExecutable = "internal-sftp"; + sftpFlags = [ "-f AUTHPRIV" "-l INFO" ]; + extraConfig = + let + pubkeyTypes = lib.strings.concatStringsSep "," [ + "sk-ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519" + ]; + in + "PubkeyAcceptedKeyTypes ${pubkeyTypes}"; + }; + }; +} |
