Sudo: Difference between revisions
No edit summary |
|||
| Line 3: | Line 3: | ||
In a nutshell, sudo permissions are defined in {{code|/etc/sudoers}} and {{code|/etc/sudoers.d/}}. Permissions are defined like so: | In a nutshell, sudo permissions are defined in {{code|/etc/sudoers}} and {{code|/etc/sudoers.d/}}. Permissions are defined like so: | ||
{{highlight|lang=text|code= | |||
%groupname workstation=/bin/command | |||
username workstation=/bin/command | |||
username workstation=(run-as user) /bin/command | |||
}} | |||
Replace any of the above with {{code|ALL}} to have it match anyone. eg: | Replace any of the above with {{code|ALL}} to have it match anyone. eg: | ||
{{highlight|lang=text|code= | |||
ALL ALL=ALL | |||
}} | |||
You can use {{code|NOPASSWD: /bin/command}} to have it not prompt for the user's password. | You can use {{code|NOPASSWD: /bin/command}} to have it not prompt for the user's password. | ||
You can verify whether your changes worked by listing sudo access: | You can verify whether your changes worked by listing sudo access: | ||
{{highlight|lang=terminal|code= | |||
# sudo -l | |||
}} | |||
== Configure sudo to include /etc/sudoers.d/ == | == Configure sudo to include /etc/sudoers.d/ == | ||
Additional sudo configs can be placed in {{code|/etc/sudoers.d/}}. Files placed here must have the permissions set to 0440. | |||
For example: | For example: | ||
Revision as of 23:29, 5 June 2017
Overview
In a nutshell, sudo permissions are defined in /etc/sudoers and /etc/sudoers.d/. Permissions are defined like so:
%groupname workstation=/bin/command
username workstation=/bin/command
username workstation=(run-as user) /bin/command
Replace any of the above with ALL to have it match anyone. eg:
ALL ALL=ALL
You can use NOPASSWD: /bin/command to have it not prompt for the user's password.
You can verify whether your changes worked by listing sudo access:
# sudo -l
Configure sudo to include /etc/sudoers.d/
Additional sudo configs can be placed in /etc/sudoers.d/. Files placed here must have the permissions set to 0440.
For example:
# cd /etc/sudoers.d
# echo "gandalf ALL=(root) NOPASSWD: /usr/sbin/dmidecode" > run_dmidecode
# chmod 0440 run_dmidecode
Ensure the #includedir directive is defined in /etc/sudoers.
Troubleshooting
sudo: sorry, you must have a tty to run sudo
Ensure that you do not require tty. Either comment out or use !requiretty .
# cat /etc/sudoers Defaults ! requiretty
If you want to run a command as another user, you could also try su. For example:
su user -c 'whoami'
sudo: no tty present and no askpass program specified
make sure you have NOPASSWD set in your sudoers file. eg:
<USER> <host>=NOPASSWD:<command>