Sudo: Difference between revisions

From Leo's Notes
This page was last edited on 24 February 2017, at 19:13.
mNo edit summary
m Text replacement - "<code>" to "{{code|"
Line 1: Line 1:


== Overview ==
== Overview ==
In a nutshell, sudo permissions are defined in <code>/etc/sudoers</code> and <code>/etc/sudoers.d/</code>. Permissions are defined like so:
In a nutshell, sudo permissions are defined in {{code|/etc/sudoers</code> and {{code|/etc/sudoers.d/</code>. Permissions are defined like so:


  %groupname workstation=/bin/command
  %groupname workstation=/bin/command
Line 7: Line 7:
  username workstation=(run-as user) /bin/command
  username workstation=(run-as user) /bin/command


Replace any of the above with <code>ALL</code> to have it match anyone. eg:
Replace any of the above with {{code|ALL</code> to have it match anyone. eg:


  ALL ALL=ALL
  ALL ALL=ALL


You can use <code>NOPASSWD: /bin/command</code> to have it not prompt for the user's password.
You can use {{code|NOPASSWD: /bin/command</code> to have it not prompt for the user's password.


You can verify whether your changes worked by listing sudo access:
You can verify whether your changes worked by listing sudo access:
Line 19: Line 19:
== Configure sudo to include /etc/sudoers.d/ ==
== Configure sudo to include /etc/sudoers.d/ ==


For the configs in <code>/etc/sudoers.d/</code> to work, you must place an existing file with perms set to 0440 into <code>/etc/sudoers.d/</code>.  
For the configs in {{code|/etc/sudoers.d/</code> to work, you must place an existing file with perms set to 0440 into {{code|/etc/sudoers.d/</code>.  


'''You cannot create the file directly in <code>/etc/sudoers.d/</code>''' because it will not work!
'''You cannot create the file directly in {{code|/etc/sudoers.d/</code>''' because it will not work!


Also ensure the <code>#includedir</code> directive is defined in <code>/etc/sudoers</code>.
Also ensure the {{code|#includedir</code> directive is defined in {{code|/etc/sudoers</code>.


== Troubleshooting ==
== Troubleshooting ==
Line 33: Line 33:
  Defaults  ! requiretty
  Defaults  ! requiretty


If you want to run a command as another user, you could also try <code>su</code>. For example:
If you want to run a command as another user, you could also try {{code|su</code>. For example:
  su user -c 'whoami'
  su user -c 'whoami'



Revision as of 19:13, 24 February 2017

Overview

In a nutshell, sudo permissions are defined in {{code|/etc/sudoers and {{code|/etc/sudoers.d/. Permissions are defined like so:

%groupname workstation=/bin/command
username workstation=/bin/command
username workstation=(run-as user) /bin/command

Replace any of the above with {{code|ALL to have it match anyone. eg:

ALL ALL=ALL

You can use {{code|NOPASSWD: /bin/command to have it not prompt for the user's password.

You can verify whether your changes worked by listing sudo access:

sudo -l


Configure sudo to include /etc/sudoers.d/

For the configs in {{code|/etc/sudoers.d/ to work, you must place an existing file with perms set to 0440 into {{code|/etc/sudoers.d/.

You cannot create the file directly in {{code|/etc/sudoers.d/ because it will not work!

Also ensure the {{code|#includedir directive is defined in {{code|/etc/sudoers.

Troubleshooting

sudo: sorry, you must have a tty to run sudo

Ensure that you do not require tty. Either comment out or use !requiretty .

# cat /etc/sudoers
Defaults   ! requiretty

If you want to run a command as another user, you could also try {{code|su. For example:

su user -c 'whoami'

sudo: no tty present and no askpass program specified

make sure you have NOPASSWD set in your sudoers file. eg:

 <USER> <host>=NOPASSWD:<command>