From 7e3ed1d2c5d0fd10bc390a60de27e2e006780f16 Mon Sep 17 00:00:00 2001 From: Artem Sheremet Date: Tue, 29 Sep 2026 16:12:17 +0000 Subject: [PATCH] Downgrade hostKeys to mkDefault --- modules/sshd.nix | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/modules/sshd.nix b/modules/sshd.nix index 2a89380..e65d9d0 100644 --- a/modules/sshd.nix +++ b/modules/sshd.nix @@ -1,9 +1,13 @@ -_: { +{ lib, ... }: { services.openssh = { enable = true; settings.PasswordAuthentication = false; settings.KbdInteractiveAuthentication = false; - hostKeys = [ + + # mkDefault (p1000) overrides nixpkgs-provided mkOptionDefault (p1500), but + # allows further overrides by hosts with unencrypted impermanence using + # standard setter (p100). + hostKeys = lib.mkDefault [ # Generate a key if it's missing, which is normal at first boot, but can # also be a TPM failure for PCs with a TPM. # Do not generate an RSA key.