Downgrade hostKeys to mkDefault

This commit is contained in:
2026-09-29 16:12:17 +00:00
parent fe06ca8540
commit 7e3ed1d2c5
+6 -2
View File
@@ -1,9 +1,13 @@
_: {
{ lib, ... }: {
services.openssh = {
enable = true;
settings.PasswordAuthentication = false;
settings.KbdInteractiveAuthentication = false;
hostKeys = [
# mkDefault (p1000) overrides nixpkgs-provided mkOptionDefault (p1500), but
# allows further overrides by hosts with unencrypted impermanence using
# standard setter (p100).
hostKeys = lib.mkDefault [
# Generate a key if it's missing, which is normal at first boot, but can
# also be a TPM failure for PCs with a TPM.
# Do not generate an RSA key.