diff --git a/configuration/common/ssh.nix b/configuration/common/ssh.nix index e62aab5..110c670 100644 --- a/configuration/common/ssh.nix +++ b/configuration/common/ssh.nix @@ -7,6 +7,9 @@ PasswordAuthentication = false; KbdInteractiveAuthentication = false; PermitRootLogin = lib.mkDefault "no"; + + # Hotfix CVE-2024-6387 https://github.com/NixOS/nixpkgs/pull/323753 + LoginGraceTime = 0; }; services.openssh.hostKeys = lib.mkForce [ # Only create ed25519 host keys