took some hours to solve this, maybe save you some time.
note If you're doing a DISA STIG for Red Hat Enterprise Linux 10 V1R2. (FIPS) and rule id xccdf_org.ssgproject.content_rule_selinux_context_elevation_for_sudo FAILS...
following the instructions in the OpenSCAP Evaluation Report breaks sudo. :(
sudo: unconfined_u:sysadm_r:sysadm_t:s0-s0:c0.c1023 is not a valid contextlet's say 'magic' is your sys admnin account and root is locked.
set the account in SELinux..
restorecon -R -F -v /home/magic
semanage login -a -s staff_u -r s0-s0:c0.c1023 magic
but then you have a chicken and egg problem, you can create the 10-wheel-selinux file with some magic
sudo -r unconfined_r -t unconfined_t visudo -f /etc/sudoers.d/10-wheel-selinux(text of file)
%wheel ALL=(ALL) TYPE=sysadm_t ROLE=sysadm_r ALLthen you get a good transition from staff_t to sysadm_t
[magic@rhfips ~]$ id -Z
staff_u:staff_r:staff_t:s0-s0:c0.c1023
[magic@rhfips ~]$ sudo id -Z
[sudo] password for magic:
staff_u:sysadm_r:sysadm_t:s0-s0:c0.c1023
[magic@rhfips ~]$