>I see some changes have been made regarding Systemd and wheel group, 
>Shouldn't there be an entry
>in LFS /etc/group file. I see that it mentioned in BLFS "About system 
>users and groups"
Yes, thank you. There is one change required in LFS (wheel 97). Linux-PAM will get a change for pam_wheel in su. I was undecided how to present the topic, but have since decided while composing this message (see below if interested). The sudo page will get the %wheel configuration entry by default regardless of pam_wheel above.

Initially 'account sufficient pam_wheel.so trust use_uid' seems like a neat *commented* example for su (with also auth required but only the auth restriction by default). If the account line is uncommented, users of the wheel group would not be required to know the root password to su, but the auth line restricts the command to members of the wheel group (this will be default).

The pam_wheel module can also be used to *grant* perms elsewhere in combination with setuid binaries (possibly for ACLs too??). Restricting certain commands makes sense, but I'm not sure it should be default...for instance, I had briefly considered chage (and it's descendants), but think I'm only going to provide the su example in the book (consistent with other distros defaults). It is not inconceivable, however, to set the coreutils binaries setuid root, with above parameters in the individual configs and forgo sudo completely. An odd corner case, for sure, and one that is likely to be error prone, but doable none the less.

The pam_wheel check would be...odd (?) for the sudo PAM config (sudo does this on its own).


