From e14744ff801a203e652be8972413dabb58ba4073 Mon Sep 17 00:00:00 2001 From: gwg313 Date: Tue, 21 Apr 2026 00:45:28 -0400 Subject: [PATCH] fix: remove options causing sudo issues --- modules/features/security/systemd/security-systemd-sshd.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/modules/features/security/systemd/security-systemd-sshd.nix b/modules/features/security/systemd/security-systemd-sshd.nix index 09442c3..66e1439 100644 --- a/modules/features/security/systemd/security-systemd-sshd.nix +++ b/modules/features/security/systemd/security-systemd-sshd.nix @@ -6,7 +6,7 @@ { ... }: { systemd.services.sshd.serviceConfig = { - NoNewPrivileges = true; + # NoNewPrivileges = true; ProtectSystem = "strict"; ProtectHome = "read-only"; ProtectClock = true; @@ -21,7 +21,7 @@ PrivateDevices = true; RestrictNamespaces = true; RestrictRealtime = true; - RestrictSUIDSGID = true; + # RestrictSUIDSGID = true; MemoryDenyWriteExecute = true; LockPersonality = true; DevicePolicy = "closed";