feat: harden ssh

This commit is contained in:
winston 2024-09-13 18:46:54 +02:00
parent 11e2fc2b1f
commit 3908e7b52c

View file

@ -7,6 +7,13 @@
enable = true;
ports = [22];
settings = {
KexAlgorithms = [
"curve25519-sha256"
"curve25519-sha256@libssh.org"
"diffie-hellman-group16-sha512"
"diffie-hellman-group18-sha512"
"sntrup761x25519-sha512@openssh.com"
];
PasswordAuthentication = false;
PermitRootLogin = "no";
StreamLocalBindUnlink = "yes";