Sudo: Difference between revisions
No edit summary |
No edit summary |
||
| Line 1: | Line 1: | ||
== In a Nutshell == | |||
In a nutshell, sudo permissions are defined in <code>/etc/sudoers</code> and <code>/etc/sudoers.d/</code>. Permissions are defined like so: | In a nutshell, sudo permissions are defined in <code>/etc/sudoers</code> and <code>/etc/sudoers.d/</code>. Permissions are defined like so: | ||
| Line 16: | Line 17: | ||
== Configure | == Configure sudo to include /etc/sudoers.d/ == | ||
For the configs in <code>/etc/sudoers.d/</code> to work, you must place an existing file with perms set to 0440 into <code>/etc/sudoers.d/</code>. | For the configs in <code>/etc/sudoers.d/</code> to work, you must place an existing file with perms set to 0440 into <code>/etc/sudoers.d/</code>. | ||
Revision as of 15:52, 13 May 2013
In a Nutshell
In a nutshell, sudo permissions are defined in /etc/sudoers and /etc/sudoers.d/. Permissions are defined like so:
%groupname workstation=/bin/command username workstation=/bin/command username workstation=(run-as user) /bin/command
Replace any of the above with ALL to have it match anyone. eg:
ALL ALL=ALL
You can use NOPASSWD: /bin/command to have it not prompt for the user's password.
You can verify whether your changes worked by listing sudo access:
sudo -l
Configure sudo to include /etc/sudoers.d/
For the configs in /etc/sudoers.d/ to work, you must place an existing file with perms set to 0440 into /etc/sudoers.d/.
You cannot create the file directly in /etc/sudoers.d/ because it will not work!
Also ensure the #includedir directive is defined in /etc/sudoers.
Troubleshooting
sudo: sorry, you must have a tty to run sudo
Ensure that you do not require tty. Either comment out or use !requiretty .
- cat /etc/sudoers
Defaults ! requiretty
sudo: no tty present and no askpass program specified
make sure you have NOPASSWD set in your sudoers file. eg:
<USER> <host>=NOPASSWD:<command>