sshd: disable trigger limit for systemd socket

When startWhenNeeded is enabled, a brute force attack on sshd will cause
systemd to shut down the socket, locking out all SSH access to the machine.
Setting TriggerLimitIntervalSec to 0 disables this behavior.
This commit is contained in:
Ben Wolsieffer 2020-11-15 20:37:17 -05:00
parent 3858bd2817
commit f5e0f2932e

View File

@ -480,6 +480,8 @@ in
else
cfg.ports;
socketConfig.Accept = true;
# Prevent brute-force attacks from shutting down socket
socketConfig.TriggerLimitIntervalSec = 0;
};
services."sshd@" = service;