Files
flocon/modules/hardened-ssh-server.nix

15 lines
343 B
Nix

{
services.openssh = {
enable = true;
settings = {
# PermitRootLogin = "no";
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
AuthenticationMethods = "publickey";
PubkeyAuthentication = "yes";
ChallengeResponseAuthentication = "no";
X11Forwarding = false;
};
};
}