diff --git a/modules/paranoia/default.nix b/modules/paranoia/default.nix index 5e8c7a70..60d69070 100644 --- a/modules/paranoia/default.nix +++ b/modules/paranoia/default.nix @@ -27,8 +27,8 @@ in { # https://xeiaso.net/blog/paranoid-nixos-2021-07-18 # Don't set this if you need sftp - services.openssh.allowSFTP = false; services.openssh.openFirewall = false; # Lock yourself out + services.openssh.settings.AllowSFTP = false; # Limit the use of sudo to the group wheel security.sudo.execWheelOnly = true;