openssh CVE mitigation

This commit is contained in:
root 2024-07-01 12:50:45 +02:00
parent 8b59d38544
commit 9f98e49084

View file

@ -9,6 +9,7 @@
# Enable the OpenSSH daemon
services.openssh.enable = true;
services.openssh.settings.PermitRootLogin = lib.mkDefault "no";
services.openssh.settings.LoginGraceTime = 0;
services.fail2ban = {
enable = true;