37 lines
588 B
Nix

{ config, pkgs, ... }:
{
services.openssh = {
enable = true;
settings = {
Port = 22;
PasswordAuthentication = false;
PermitRootLogin = "no";
Protocol = 2;
X11Forwarding = true;
LoginGraceTime = 30;
MaxAuthTries = 3;
PermitEmptyPasswords = false;
IgnoreRhosts = true;
HostbasedAuthentication = false;
LogLevel = "INFO";
ClientAliveInterval = 300;
ClientAliveCountMax = 2;
};
authorizedKeysFiles = [ ".ssh/authorized_keys" ];
};
networking.firewall.allowedTCPPorts = [ 22 ];
}