If you want to user can su - without prompt for password you should do next:
Add user in wheel group bu editing /etc/group file and simply add user in line wheel, like next:

wheel:x:10:root, setenforce

it means that user setenforce can su - without prompt for passwd.

After this you should enable this in pam. Do this by removing comment from next line

auth sufficient pam_wheel.so trust use_uid

in /etc/pam.d/su