Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #242525
| From | Pierre-Elliott Bécue <peb@debian.org> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Don't try this at home kids |
| Date | 2021-11-30 00:00 +0100 |
| Message-ID | <DoXMS-6sm-5@gated-at.bofh.it> (permalink) |
| References | <DoXtw-6m0-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
Hello, Bob Bernstein <poobah@ruptured-duck.com> wrote on 29/11/2021 at 23:25:52+0100: > How do I tell sudo not to ask me for my password? > > It's me. I'm on my computer. I already logged in with my password. No > one else is logged on. > > I know all you purists out there are rending your garments if not your > flesh. but c'mon sudo! Can't a brother catch a break around here? > > Thank you. While I would still recommend you not to do that, here is how you can do it. man 5 sudoers reads: > PASSWD and NOPASSWD > > By default, sudo requires that a user authenticate him or herself > before running a command. This behavior can be modified via the > NOPASSWD tag. Like a Runas_Spec, the NOPASSWD tag sets a default > for the commands that follow it in the Cmnd_Spec_List. > Conversely, the PASSWD tag can be used to reverse things. For > exam‐ ple: > > ray rushmore = NOPASSWD: /bin/kill, /bin/ls, /usr/bin/lprm > > would allow the user ray to run /bin/kill, /bin/ls, and > /usr/bin/lprm as root on the machine rushmore with‐ out > authenticating himself. If we only want ray to be able to run > /bin/kill without a password the entry would be: > > ray rushmore = NOPASSWD: /bin/kill, PASSWD: /bin/ls, /usr/bin/lprm > > Note, however, that the PASSWD tag has no effect on users who are > in the group specified by the exempt_group setting. > > By default, if the NOPASSWD tag is applied to any of a user's > entries for the current host, the user will be able to run “sudo > -l” without a password. Additionally, a user may only run “sudo > -v” without a pass‐ word if all of the user's entries for the > current host have the NOPASSWD tag. This behavior may be over‐ > ridden via the verifypw and listpw options. Have a read at visudo's manpage, too. I won't give you the exact line to type, as it's a nice way to make sure you understand what you are doing. But still, you should consider not doing so, as it can bite back strongly should your computer be accessed by someone else while you're not at your desk and still logged in. Anyway, meh. -- PEB
Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread
Don't try this at home kids Bob Bernstein <poobah@ruptured-duck.com> - 2021-11-29 23:40 +0100
Re: Don't try this at home kids Jeremy Ardley <jeremy@ardley.org> - 2021-11-29 23:50 +0100
Re: Don't try this at home kids Jude DaShiell <jdashiel@panix.com> - 2021-11-29 23:50 +0100
Re: Don't try this at home kids David Wright <deblis@lionunicorn.co.uk> - 2021-11-30 05:50 +0100
Re: Don't try this at home kids Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-11-30 07:00 +0100
Re: Don't try this at home kids Paul Johnson <baloo@ursamundi.org> - 2021-11-30 18:20 +0100
Re: Don't try this at home kids Greg Wooledge <greg@wooledge.org> - 2021-11-30 19:20 +0100
Re: Don't try this at home kids David Wright <deblis@lionunicorn.co.uk> - 2021-12-03 03:50 +0100
Re: Don't try this at home kids Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-11-30 20:40 +0100
Re: Don't try this at home kids Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-05 16:40 +0100
Re: Don't try this at home kids Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-05 16:50 +0100
Re: Don't try this at home kids Darac Marjal <mailinglist@darac.org.uk> - 2021-11-30 00:00 +0100
Re: Don't try this at home kids "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2021-11-30 00:20 +0100
Re: Don't try this at home kids Jeremy Ardley <jeremy@ardley.org> - 2021-11-30 00:30 +0100
Re: Don't try this at home kids John Hasler <john@sugarbit.com> - 2021-11-30 01:10 +0100
Re: Don't try this at home kids Bob Bernstein <poobah@ruptured-duck.com> - 2021-11-30 01:10 +0100
Re: Don't try this at home kids Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-11-30 01:30 +0100
Re: Don't try this at home kids Tom Dial <tddial@comcast.net> - 2021-11-30 05:30 +0100
Re: Don't try this at home kids Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-03 05:50 +0100
Re: Don't try this at home kids Igor Korot <ikorot01@gmail.com> - 2021-11-30 00:00 +0100
Re: Don't try this at home kids Pierre-Elliott Bécue <peb@debian.org> - 2021-11-30 00:00 +0100
csiph-web