Sudo: Difference between revisions

From Leo's Notes
This page was last edited on 5 June 2017, at 23:02.
m Text replacement - "</code>" to "}}"
Line 21: Line 21:
For the configs in {{code|/etc/sudoers.d/}} to work, you must place an existing file with perms set to 0440 into {{code|/etc/sudoers.d/}}.  
For the configs in {{code|/etc/sudoers.d/}} to work, you must place an existing file with perms set to 0440 into {{code|/etc/sudoers.d/}}.  


'''You cannot create the file directly in {{code|/etc/sudoers.d/}}''' because it will not work!
For example:
{{highlight|lang=terminal|code=
# cd /etc/sudoers.d
# echo "gandalf ALL=(root) NOPASSWD: /usr/sbin/dmidecode" > run_dmidecode
# chmod 0440 run_dmidecode
}}


Also ensure the {{code|#includedir}} directive is defined in {{code|/etc/sudoers}}.
Ensure the {{code|#includedir}} directive is defined in {{code|/etc/sudoers}}.


== Troubleshooting ==
== Troubleshooting ==

Revision as of 23:02, 5 June 2017

Overview

In a nutshell, sudo permissions are defined in /etc/sudoers and /etc/sudoers.d/. Permissions are defined like so:

%groupname workstation=/bin/command
username workstation=/bin/command
username workstation=(run-as user) /bin/command

Replace any of the above with ALL to have it match anyone. eg:

ALL ALL=ALL

You can use NOPASSWD: /bin/command to have it not prompt for the user's password.

You can verify whether your changes worked by listing sudo access:

sudo -l


Configure sudo to include /etc/sudoers.d/

For the configs in /etc/sudoers.d/ to work, you must place an existing file with perms set to 0440 into /etc/sudoers.d/.

For example:

# cd /etc/sudoers.d
# echo "gandalf ALL=(root) NOPASSWD: /usr/sbin/dmidecode" > run_dmidecode
# chmod 0440 run_dmidecode

Ensure the #includedir directive is defined in /etc/sudoers.

Troubleshooting

sudo: sorry, you must have a tty to run sudo

Ensure that you do not require tty. Either comment out or use !requiretty .

# cat /etc/sudoers
Defaults   ! requiretty

If you want to run a command as another user, you could also try su. For example:

su user -c 'whoami'

sudo: no tty present and no askpass program specified

make sure you have NOPASSWD set in your sudoers file. eg:

 <USER> <host>=NOPASSWD:<command>