diff --git a/groups/all/default.nix b/groups/all/default.nix index fac958f..0ba6d11 100644 --- a/groups/all/default.nix +++ b/groups/all/default.nix @@ -7,9 +7,10 @@ ./modules/flatpak.nix ]; - # NOTE: mkDefault is 1000 and mkForce is 50 - # NOTE: so this is like a second mkDefault - security.sudo.wheelNeedsPassword = true; + security.sudo-rs = { + enable = true; + wheelNeedsPassword = lib.mkOverride 200 true; + }; networking = { networkmanager.enable = true; diff --git a/groups/cryos/default.nix b/groups/cryos/default.nix index 1f37683..cadbee6 100644 --- a/groups/cryos/default.nix +++ b/groups/cryos/default.nix @@ -86,10 +86,7 @@ }; }; - security = { - rtkit.enable = true; # I *think* this is for pipewire - sudo.wheelNeedsPassword = lib.mkDefault true; - }; + security.rtkit.enable = true; # I *think* this is for pipewire # ---- ENVIRONMENT VARIABLES ---- environment = { diff --git a/groups/server/default.nix b/groups/server/default.nix index 18f1256..cb55017 100644 --- a/groups/server/default.nix +++ b/groups/server/default.nix @@ -19,10 +19,6 @@ defaults.email = "eclarkboman@gmail.com"; }; - sudo = { - enable = true; - wheelNeedsPassword = true; - }; # allow SSH keys for passwordless auth pam = { sshAgentAuth.enable = true; diff --git a/hosts/myputer/default.nix b/hosts/myputer/default.nix index a5a28e5..1a05530 100755 --- a/hosts/myputer/default.nix +++ b/hosts/myputer/default.nix @@ -46,7 +46,7 @@ }; }; - security.sudo.wheelNeedsPassword = lib.mkForce false; + security.sudo-rs.wheelNeedsPassword = lib.mkForce false; # ---- SYSTEM PACKAGES ----- environment.systemPackages = with pkgs; [