diff --git a/modules/sshd.nix b/modules/sshd.nix index 2a89380..e65d9d0 100644 --- a/modules/sshd.nix +++ b/modules/sshd.nix @@ -1,9 +1,13 @@ -_: { +{ lib, ... }: { services.openssh = { enable = true; settings.PasswordAuthentication = false; settings.KbdInteractiveAuthentication = false; - hostKeys = [ + + # mkDefault (p1000) overrides nixpkgs-provided mkOptionDefault (p1500), but + # allows further overrides by hosts with unencrypted impermanence using + # standard setter (p100). + hostKeys = lib.mkDefault [ # Generate a key if it's missing, which is normal at first boot, but can # also be a TPM failure for PCs with a TPM. # Do not generate an RSA key.