{ ... }: { nix.settings = { trusted-users = ["root" "@wheel"]; }; security = { sudo = { enable = true; wheelNeedsPassword = true; }; pam = { sshAgentAuth.enable = true; services.sudo.sshAgentAuth = true; # pam_ssh_agent_auth module }; }; }