Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #242525

Re: Don't try this at home kids

From Pierre-Elliott Bécue <peb@debian.org>
Newsgroups linux.debian.user
Subject Re: Don't try this at home kids
Date 2021-11-30 00:00 +0100
Message-ID <DoXMS-6sm-5@gated-at.bofh.it> (permalink)
References <DoXtw-6m0-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hello,

Bob Bernstein <poobah@ruptured-duck.com> wrote on 29/11/2021 at 23:25:52+0100:

> How do I tell sudo not to ask me for my password?
>
> It's me. I'm on my computer. I already logged in with my password. No
> one else is logged on.
>
> I know all you purists out there are rending your garments if not your
> flesh. but c'mon sudo! Can't a brother catch a break around here?
>
> Thank you.

While I would still recommend you not to do that, here is how you can do
it.

man 5 sudoers reads:

>     PASSWD and NOPASSWD
>
>       By default, sudo requires that a user authenticate him or herself
>       before running a command.  This behavior can be modified via the
>       NOPASSWD tag.  Like a Runas_Spec, the NOPASSWD tag sets a default
>       for the commands that follow it in the Cmnd_Spec_List.
>       Conversely, the PASSWD tag can be used to reverse things.  For
>       exam‐ ple:
>
>       ray     rushmore = NOPASSWD: /bin/kill, /bin/ls, /usr/bin/lprm
>
>       would allow the user ray to run /bin/kill, /bin/ls, and
>       /usr/bin/lprm as root on the machine rushmore with‐ out
>       authenticating himself.  If we only want ray to be able to run
>       /bin/kill without a password the entry would be:
>
>       ray     rushmore = NOPASSWD: /bin/kill, PASSWD: /bin/ls, /usr/bin/lprm
>
>       Note, however, that the PASSWD tag has no effect on users who are
>       in the group specified by the exempt_group setting.
>
>       By default, if the NOPASSWD tag is applied to any of a user's
>       entries for the current host, the user will be able to run “sudo
>       -l” without a password.  Additionally, a user may only run “sudo
>       -v” without a pass‐ word if all of the user's entries for the
>       current host have the NOPASSWD tag.  This behavior may be over‐
>       ridden via the verifypw and listpw options.

Have a read at visudo's manpage, too. I won't give you the exact line to
type, as it's a nice way to make sure you understand what you are doing.

But still, you should consider not doing so, as it can bite back
strongly should your computer be accessed by someone else while you're
not at your desk and still logged in.

Anyway, meh.

-- 
PEB

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Don't try this at home kids Bob Bernstein <poobah@ruptured-duck.com> - 2021-11-29 23:40 +0100
  Re: Don't try this at home kids Jeremy Ardley <jeremy@ardley.org> - 2021-11-29 23:50 +0100
    Re: Don't try this at home kids Jude DaShiell <jdashiel@panix.com> - 2021-11-29 23:50 +0100
      Re: Don't try this at home kids David Wright <deblis@lionunicorn.co.uk> - 2021-11-30 05:50 +0100
        Re: Don't try this at home kids Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-11-30 07:00 +0100
          Re: Don't try this at home kids Paul Johnson <baloo@ursamundi.org> - 2021-11-30 18:20 +0100
            Re: Don't try this at home kids Greg Wooledge <greg@wooledge.org> - 2021-11-30 19:20 +0100
              Re: Don't try this at home kids David Wright <deblis@lionunicorn.co.uk> - 2021-12-03 03:50 +0100
            Re: Don't try this at home kids Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-11-30 20:40 +0100
              Re: Don't try this at home kids Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-05 16:40 +0100
        Re: Don't try this at home kids Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-05 16:50 +0100
    Re: Don't try this at home kids Darac Marjal <mailinglist@darac.org.uk> - 2021-11-30 00:00 +0100
    Re: Don't try this at home kids "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2021-11-30 00:20 +0100
      Re: Don't try this at home kids Jeremy Ardley <jeremy@ardley.org> - 2021-11-30 00:30 +0100
      Re: Don't try this at home kids John Hasler <john@sugarbit.com> - 2021-11-30 01:10 +0100
      Re: Don't try this at home kids Bob Bernstein <poobah@ruptured-duck.com> - 2021-11-30 01:10 +0100
      Re: Don't try this at home kids Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-11-30 01:30 +0100
        Re: Don't try this at home kids Tom Dial <tddial@comcast.net> - 2021-11-30 05:30 +0100
          Re: Don't try this at home kids Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-03 05:50 +0100
  Re: Don't try this at home kids Igor Korot <ikorot01@gmail.com> - 2021-11-30 00:00 +0100
  Re: Don't try this at home kids Pierre-Elliott Bécue <peb@debian.org> - 2021-11-30 00:00 +0100

csiph-web