mirror of
https://github.com/XNM1/linux-nixos-hyprland-config-dotfiles.git
synced 2025-09-15 09:45:58 +03:00
🔒 feat(security): replace sudo
with sudo-rs
- Enable `sudo-rs` with wheel-only execution - Disable legacy `sudo` - Update AppArmor and U2F configs for `sudo-rs` - Update Yubikey U2F auth for `sudo-rs`
This commit is contained in:
@@ -10,6 +10,11 @@
|
||||
# };
|
||||
|
||||
# Enable Security Services
|
||||
security.sudo-rs = {
|
||||
enable = true;
|
||||
execWheelOnly = true;
|
||||
};
|
||||
security.sudo.enable = false;
|
||||
users.users.root.hashedPassword = "!";
|
||||
security.tpm2 = {
|
||||
enable = true;
|
||||
@@ -28,7 +33,7 @@
|
||||
security.pam.services = {
|
||||
login.enableAppArmor = true;
|
||||
sshd.enableAppArmor = true;
|
||||
sudo.enableAppArmor = true;
|
||||
sudo-rs.enableAppArmor = true;
|
||||
su.enableAppArmor = true;
|
||||
greetd.enableAppArmor = true;
|
||||
u2f.enableAppArmor = true;
|
||||
|
Reference in New Issue
Block a user