diff options
author | ene <ene@sils.li> | 2023-01-17 06:50:27 +0100 |
---|---|---|
committer | Gitea <gitea@fake.local> | 2023-01-17 19:10:02 +0100 |
commit | f0edcec82eadf7dc57ea0a12562717d40cff2cb6 (patch) | |
tree | afaa6956d1df5a1444627647f98bc5500365d8c7 /configuration.nix | |
parent | Merge pull request 'Feat: Added /boot as persistent subvolume' (#10) from ser... (diff) | |
download | nixos-server-f0edcec82eadf7dc57ea0a12562717d40cff2cb6.tar.gz nixos-server-f0edcec82eadf7dc57ea0a12562717d40cff2cb6.zip |
Sec: Persistent ssh host keys
I changed the valid ssh-host-keys from both rsa and ed25519 to only ed25519 and moved them to `/srv/ssh` to make them persistent. In addition to that, I also increased the rounds for the ed25519 key to 1000. This fixes the ssh-host-key issue introduced by pull request #5. Fixes: #5
Diffstat (limited to '')
-rw-r--r-- | configuration.nix | 12 |
1 files changed, 2 insertions, 10 deletions
diff --git a/configuration.nix b/configuration.nix index 600201d..4d1f8d9 100644 --- a/configuration.nix +++ b/configuration.nix @@ -3,7 +3,9 @@ ./hardware-configuration.nix ./packages.nix ./networking.nix # network configuration that just works + ./services/minecraft.nix + ./services/opensshd.nix ]; boot.cleanTmpDir = true; @@ -11,16 +13,6 @@ networking.hostName = "server1"; networking.domain = "vhack.eu"; - # openssh config - services.openssh = { - enable = true; - passwordAuthentication = false; - extraConfig = "PrintMotd yes\n"; # this could be done with pam - }; - users.users.root.openssh.authorizedKeys.keys = [ - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGBFuTNNn71Rhfnop2cdz3r/RhWWlCePnSBOhTBbu2ME soispha" - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIG63gxw8JePmrC8Fni0pLV4TnPBhCPmSV9FYEdva+6s7 sils" - ]; system.stateVersion = "22.11"; } |