puter/common/ssh.nix

34 lines
635 B
Nix
Raw Normal View History

2024-02-24 23:51:34 +00:00
{
lib,
pkgs,
...
}: {
2024-07-01 22:06:05 +00:00
age.identityPaths = ["/etc/ssh/ssh_host_ed25519_key"];
2024-02-21 21:08:11 +00:00
services.openssh = {
enable = true;
openFirewall = true;
hostKeys = [
{
path = "/etc/ssh/ssh_host_ed25519_key";
type = "ed25519";
}
];
settings = {
2024-09-15 15:17:44 +00:00
PermitRootLogin = "forced-commands-only";
2024-02-21 21:08:11 +00:00
PasswordAuthentication = false;
};
};
2024-02-24 23:51:34 +00:00
programs.ssh = {
startAgent = true;
2024-07-01 22:06:05 +00:00
enableAskPassword = true;
2024-02-24 23:51:34 +00:00
askPassword = lib.getExe' pkgs.ksshaskpass "ksshaskpass";
};
2024-02-04 20:51:11 +00:00
environment.etc."ssh/ssh_config".text = lib.mkAfter ''
Compression yes
ServerAliveInterval 60
'';
}