Sudo: Difference between revisions
Created page with " %group workstation=/bin/command user workstation=/bin/command You can use <code>NOPASSWD: /bin/command</code> to have it not prompt for the user's password. If you put ..." |
No edit summary |
||
| Line 1: | Line 1: | ||
In a nutshell, sudo permissions are defined in <code>/etc/sudoers</code> and <code>/etc/sudoers.d/</code>. Permissions are defined like so: | |||
%groupname workstation=/bin/command | |||
username workstation=/bin/command | |||
username workstation=(run-as user) /bin/command | |||
Replace any of the above with <code>ALL</code> to have it match anyone. eg: | |||
ALL ALL=ALL | |||
You can use <code>NOPASSWD: /bin/command</code> to have it not prompt for the user's password. | You can use <code>NOPASSWD: /bin/command</code> to have it not prompt for the user's password. | ||
You can verify whether your changes worked by listing sudo access: | |||
sudo -l | |||
== Configure using /etc/sudoers.d/ == | |||
For the configs in <code>/etc/sudoers.d/</code> to work, you must place an existing file with perms set to 0440 into <code>/etc/sudoers.d/</code>. You cannot create the file directly in <code>/etc/sudoers.d/</code> because it will not work. | |||
Also ensure the <code>#includedir</code> directive is defined in <code>/etc/sudoers</code>. | |||
[[Category:Linux]] | [[Category:Linux]] | ||
Revision as of 16:01, 7 May 2013
In a nutshell, sudo permissions are defined in /etc/sudoers and /etc/sudoers.d/. Permissions are defined like so:
%groupname workstation=/bin/command username workstation=/bin/command username workstation=(run-as user) /bin/command
Replace any of the above with ALL to have it match anyone. eg:
ALL ALL=ALL
You can use NOPASSWD: /bin/command to have it not prompt for the user's password.
You can verify whether your changes worked by listing sudo access:
sudo -l
Configure using /etc/sudoers.d/
For the configs in /etc/sudoers.d/ to work, you must place an existing file with perms set to 0440 into /etc/sudoers.d/. You cannot create the file directly in /etc/sudoers.d/ because it will not work.
Also ensure the #includedir directive is defined in /etc/sudoers.