openssh: support prohibit-password for permitRootLogin

See 1dc8d93ce6

I also made it the default.
This commit is contained in:
Anmol Sethi 2016-10-01 13:23:56 -04:00
parent 98a8146428
commit 6891bb1c59
No known key found for this signature in database
GPG key ID: 427400A70839B0ED
6 changed files with 7 additions and 7 deletions

View file

@ -24,7 +24,7 @@ with lib;
# Allow root logins only using the SSH key that the user specified
# at instance creation time, ping client connections to avoid timeouts
services.openssh.enable = true;
services.openssh.permitRootLogin = "without-password";
services.openssh.permitRootLogin = "prohibit-password";
services.openssh.extraConfig = ''
ClientAliveInterval 180
'';