[Hardening] prohibit root ssh login entirely in hardcore mode

This commit is contained in:
Antoine Viallon 2024-03-08 23:27:30 +01:00
parent 3080d90d2c
commit 06398f02a6
Signed by: aviallon
GPG key ID: 186FC35EDEB25716

View file

@ -43,7 +43,10 @@ in
security.sudo.execWheelOnly = true;
services.openssh.settings.PermitRootLogin = "prohibit-password";
services.openssh.settings.PermitRootLogin =
if cfg.hardcore then
"no"
else "prohibit-password";
security.apparmor.enable = true;
services.dbus.apparmor = "enabled";