feat: harden openssh server

This commit is contained in:
uku 2024-06-20 16:49:12 +02:00
parent 68f719b7ff
commit b794652a36
Signed by: uku
SSH key fingerprint: SHA256:4P0aN6M8ajKukNi6aPOaX0LacanGYtlfjmN+m/sHY/o
2 changed files with 13 additions and 6 deletions

View file

@ -113,11 +113,6 @@ in {
}; };
services = { services = {
openssh = {
enable = true;
openFirewall = lib.mkDefault false;
};
vscode-server.enable = true; vscode-server.enable = true;
resolved = { resolved = {

View file

@ -1,3 +1,15 @@
{ {
services.tailscale.extraUpFlags = ["--advertise-exit-node"]; services = {
tailscale.extraUpFlags = ["--advertise-exit-node"];
openssh = {
enable = true;
settings = {
PermitRootLogin = "no";
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
X11Forwarding = false;
};
};
};
} }