diff --git a/nixos/security-services.nix b/nixos/security-services.nix index 38924cd..6e5bf59 100644 --- a/nixos/security-services.nix +++ b/nixos/security-services.nix @@ -10,6 +10,11 @@ # }; # Enable Security Services + security.sudo-rs = { + enable = true; + execWheelOnly = true; + }; + security.sudo.enable = false; users.users.root.hashedPassword = "!"; security.tpm2 = { enable = true; @@ -28,7 +33,7 @@ security.pam.services = { login.enableAppArmor = true; sshd.enableAppArmor = true; - sudo.enableAppArmor = true; + sudo-rs.enableAppArmor = true; su.enableAppArmor = true; greetd.enableAppArmor = true; u2f.enableAppArmor = true; diff --git a/nixos/yubikey.nix b/nixos/yubikey.nix index c4369c9..6815f04 100644 --- a/nixos/yubikey.nix +++ b/nixos/yubikey.nix @@ -14,7 +14,7 @@ security.pam.services = { greetd.u2fAuth = true; - sudo.u2fAuth = true; + sudo-rs.u2fAuth = true; hyprlock.u2fAuth = true; };