Enable audit on server systems only
This commit is contained in:
parent
6eb50d3a8f
commit
a091fb2a69
@ -18,16 +18,7 @@
|
||||
|
||||
console.keyMap = "uk";
|
||||
|
||||
security = {
|
||||
auditd.enable = true;
|
||||
audit = {
|
||||
enable = true;
|
||||
rules = [
|
||||
"-a exit,always -F arch=b64 -S execve"
|
||||
];
|
||||
};
|
||||
sudo.execWheelOnly = true;
|
||||
};
|
||||
security.sudo.execWheelOnly = true;
|
||||
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
|
@ -7,6 +7,16 @@
|
||||
|
||||
documentation.enable = false;
|
||||
|
||||
security = {
|
||||
auditd.enable = true;
|
||||
audit = {
|
||||
enable = true;
|
||||
rules = [
|
||||
"-a exit,always -F arch=b64 -S execve"
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
modules.networking.tailscale = {
|
||||
enable = true;
|
||||
restrictSSH = false;
|
||||
|
Loading…
x
Reference in New Issue
Block a user