summary refs log tree commit diff stats
path: root/modules/by-name/op/openssh/module.nix
diff options
context:
space:
mode:
authorBenedikt Peetz <benedikt.peetz@b-peetz.de>2024-12-20 13:58:21 +0100
committerBenedikt Peetz <benedikt.peetz@b-peetz.de>2024-12-20 13:58:21 +0100
commit33639143ea50404a04bc4c454435aff1bd79dd4b (patch)
treeede4b6832bb86ac30281fc22700ae1fe40658f37 /modules/by-name/op/openssh/module.nix
parentfix(treewide): Update to nixos release 24.11 (diff)
downloadnixos-server-33639143ea50404a04bc4c454435aff1bd79dd4b.tar.gz
nixos-server-33639143ea50404a04bc4c454435aff1bd79dd4b.zip
refactor({modules,test}): Migrate to a `by-name` structure
Diffstat (limited to 'modules/by-name/op/openssh/module.nix')
-rw-r--r--modules/by-name/op/openssh/module.nix31
1 files changed, 31 insertions, 0 deletions
diff --git a/modules/by-name/op/openssh/module.nix b/modules/by-name/op/openssh/module.nix
new file mode 100644
index 0000000..30d16a6
--- /dev/null
+++ b/modules/by-name/op/openssh/module.nix
@@ -0,0 +1,31 @@
+{
+  config,
+  lib,
+  ...
+}: let
+  cfg = config.vhack.openssh;
+in {
+  options.vhack.openssh = {
+    enable = lib.mkEnableOption ''
+      a sane openssh implementation.
+    '';
+  };
+
+  config = lib.mkIf cfg.enable {
+    services.openssh = {
+      enable = true;
+      settings.PasswordAuthentication = false;
+      hostKeys = [
+        {
+          # See the explanation for this in /system/impermanence/mods/openssh.nix
+          # path = "/var/lib/sshd/ssh_host_ed25519_key";
+
+          # FIXME: Remove this workaround
+          path = "/srv/var/lib/sshd/ssh_host_ed25519_key";
+          rounds = 1000;
+          type = "ed25519";
+        }
+      ];
+    };
+  };
+}