Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #242636

Re: Don't try this at home kids

From David Wright <deblis@lionunicorn.co.uk>
Newsgroups linux.debian.user
Subject Re: Don't try this at home kids
Date 2021-12-03 03:50 +0100
Message-ID <Dq6O6-6UI-1@gated-at.bofh.it> (permalink)
References (2 earlier) <DoXDb-6pd-3@gated-at.bofh.it> <Dp3fA-1hT-9@gated-at.bofh.it> <Dp4lj-1Za-3@gated-at.bofh.it> <DpeXo-8rM-7@gated-at.bofh.it> <DpfTs-yq-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue 30 Nov 2021 at 13:15:56 (-0500), Greg Wooledge wrote:
> On Tue, Nov 30, 2021 at 11:12:49AM -0600, Paul Johnson wrote:
> > On Mon, Nov 29, 2021 at 11:57 PM Joe Pfeiffer <pfeiffer@cs.nmsu.edu> wrote:
> > > David Wright <deblis@lionunicorn.co.uk> writes:
> > > > As /etc/sudoers already contains the line:
> > > >
> > > >   %sudo   ALL=(ALL:ALL) ALL
> > > >
> > > > one should be able to achieve the same effect by
> > > > adding the user to the sudo group.
> > >
> > > Near as I can tell from my experience, that doesn't work around the
> > > password requirement.

Yes, I don't really approve of the original request. It's one thing
to allow using a closed set of specific, routine commands without
a password, as I do, but to open up the whole system by typing sudo
at the start of a line seems like going a bit too far for me.

It's bad enough that after typing it once, AIUI, you get 15 mins of
passwordless freedom. However, can you not use that to your advantage
by increasing the default timeout to a value that suits you?

Presumably, typing the password once in, say, 9 hours, is not too
onerous, and a major advantage is that it's revokable, merely by
closing the terminal that you typed it into. OTOH, NOPASSWD: leaves
all your sessionS wide open, as it's not revokable.

> > Make sure you log out and log back in after you do 'adduser joe sudo' (or
> > whatever your username is). Group permissions are generally only effective
> > as they were at the time of that session's login.
> 
> What you said is correct, but it doesn't contradict the paragraph that
> you cited.
> 
> Adding yourself to the sudo group (and then re-logging-in) allows you
> to use sudo.  It doesn't skip the password requirement.
> 
> To skip the password requirement, you need to make edits, either to the
> main sudoers file or to a drop-in file.  Instructions have already been
> given earlier in this thread.  It involves adding the string NOPASSWD
> and some punctuation in the right position in a ridiculously overengineered
> file.

It's difficult to imagine using the flexibility that   man sudoers
demonstrates. But then, I've never had to administer a system that's
subject to the excessive ingenuity that some people (think students)
can show.

Cheers,
David.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Don't try this at home kids Bob Bernstein <poobah@ruptured-duck.com> - 2021-11-29 23:40 +0100
  Re: Don't try this at home kids Jeremy Ardley <jeremy@ardley.org> - 2021-11-29 23:50 +0100
    Re: Don't try this at home kids Jude DaShiell <jdashiel@panix.com> - 2021-11-29 23:50 +0100
      Re: Don't try this at home kids David Wright <deblis@lionunicorn.co.uk> - 2021-11-30 05:50 +0100
        Re: Don't try this at home kids Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-11-30 07:00 +0100
          Re: Don't try this at home kids Paul Johnson <baloo@ursamundi.org> - 2021-11-30 18:20 +0100
            Re: Don't try this at home kids Greg Wooledge <greg@wooledge.org> - 2021-11-30 19:20 +0100
              Re: Don't try this at home kids David Wright <deblis@lionunicorn.co.uk> - 2021-12-03 03:50 +0100
            Re: Don't try this at home kids Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2021-11-30 20:40 +0100
              Re: Don't try this at home kids Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-05 16:40 +0100
        Re: Don't try this at home kids Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-05 16:50 +0100
    Re: Don't try this at home kids Darac Marjal <mailinglist@darac.org.uk> - 2021-11-30 00:00 +0100
    Re: Don't try this at home kids "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2021-11-30 00:20 +0100
      Re: Don't try this at home kids Jeremy Ardley <jeremy@ardley.org> - 2021-11-30 00:30 +0100
      Re: Don't try this at home kids John Hasler <john@sugarbit.com> - 2021-11-30 01:10 +0100
      Re: Don't try this at home kids Bob Bernstein <poobah@ruptured-duck.com> - 2021-11-30 01:10 +0100
      Re: Don't try this at home kids Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-11-30 01:30 +0100
        Re: Don't try this at home kids Tom Dial <tddial@comcast.net> - 2021-11-30 05:30 +0100
          Re: Don't try this at home kids Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-03 05:50 +0100
  Re: Don't try this at home kids Igor Korot <ikorot01@gmail.com> - 2021-11-30 00:00 +0100
  Re: Don't try this at home kids Pierre-Elliott Bécue <peb@debian.org> - 2021-11-30 00:00 +0100

csiph-web