diff --git a/modules/nixos/common/security.nix b/modules/nixos/common/security.nix index 809e8343e..863b76c30 100644 --- a/modules/nixos/common/security.nix +++ b/modules/nixos/common/security.nix @@ -1,3 +1,4 @@ +{ inputs, pkgs, ... }: { # Make sure that the firewall is enabled, even if it's the default. networking.firewall.enable = true; @@ -5,6 +6,11 @@ # allow to access emergency shell with a password boot.initrd.systemd.emergencyAccess = "$6$he2fblfl/H7I.kvz$WbSCMXu8ztmqfj5jG4czqvu/rkMHxufxqHgy1urzXFSN.jZB4QiW5lOjR08vk8pZTyim3TT1wFkMaNE9zZ3sc1"; + boot.initrd.network.ssh = { + enable = true; + authorizedKeyFiles = pkgs.lib.filesystem.listFilesRecursive "${toString inputs.self}/users/keys"; + }; + services.openssh = { hostKeys = [ {