Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #241295 > unrolled thread

dead lock

Started byPierre Frenkiel <pierre.frenkiel@gmail.com>
First post2021-10-14 15:00 +0200
Last post2021-10-14 16:30 +0200
Articles 9 — 6 participants

Back to article view | Back to linux.debian.user


Contents

  dead lock Pierre Frenkiel <pierre.frenkiel@gmail.com> - 2021-10-14 15:00 +0200
    Re: dead lock Greg Wooledge <greg@wooledge.org> - 2021-10-14 15:20 +0200
      Re: dead lock Keith Bainbridge <keithrbaugroups@gmail.com> - 2021-10-16 06:10 +0200
        Re: dead lock Greg Wooledge <greg@wooledge.org> - 2021-10-16 15:40 +0200
          Re: dead lock Keith Bainbridge <keithrbaugroups@gmail.com> - 2021-10-17 09:00 +0200
    Re: dead lock Peter Ehlert <pb21a@sdi-baja.com> - 2021-10-14 15:40 +0200
      security of debian default sudoers file (was: dead lock) Gregor Zattler <telegraph@gmx.net> - 2021-10-17 11:50 +0200
        Re: security of debian default sudoers file (was: dead lock) Keith Bainbridge <keithrbaugroups@gmail.com> - 2021-10-17 12:20 +0200
    Re: dead lock Stanislav Vlasov <stanislav.v.v@gmail.com> - 2021-10-14 16:30 +0200

#241295 — dead lock

FromPierre Frenkiel <pierre.frenkiel@gmail.com>
Date2021-10-14 15:00 +0200
Subjectdead lock
Message-ID<D88v0-2T1-3@gated-at.bofh.it>
hi
After  a Debian install on my amd64 laptop, I'm faced to what looks like
a beautiful dead lock:
I wanted to set a root account, but that was refused because I'm not
in /etc/sudoers, and to put me in this file, I need root privilege!
I suppose that there is a solution, but I couldn't find it.
Any idea?

best regards,
-- 
Pierre Frenkiel

[toc] | [next] | [standalone]


#241296

FromGreg Wooledge <greg@wooledge.org>
Date2021-10-14 15:20 +0200
Message-ID<D88Om-3fd-15@gated-at.bofh.it>
In reply to#241295
On Thu, Oct 14, 2021 at 02:54:26PM +0200, Pierre Frenkiel wrote:
> After  a Debian install on my amd64 laptop, I'm faced to what looks like
> a beautiful dead lock:
> I wanted to set a root account, but that was refused because I'm not
> in /etc/sudoers, and to put me in this file, I need root privilege!
> I suppose that there is a solution, but I couldn't find it.
> Any idea?

During the installation, you are asked for a root password, and you
are given the option to leave it blank.  If you supply a root password,
then you can use that to login directly as root on a console.  (Press
Ctrl-Alt-F2 to get to a console.  Press Ctrl-Alt-F1 or -F7 to get back
to your X or Wayland session, if you installed a display manager.)

If you left it blank, then sudo should have been installed, and your
initial user account should have added to the sudo group.  (You can see
your current group memberships by running "id" in a shell.)

If for some reason you've forgotten the root password that you used
during installation, or you've lost your membership in the sudo group,
then you can add "init=/bin/bash" to the kernel parameters in GRUB,
re-mount the root file system read/write, run the "passwd root" command
to set a new root password, and then reboot again.

(Some people do a bind-mount thing in there as well, but I'm not sure
what purpose that serves if you're only going to run passwd.)

But I find it strange that you claim to have this problem "After a Debian
install" which implies that it's a thing you did quite recently.  I
suspect we're not getting the whole picture here....

[toc] | [prev] | [next] | [standalone]


#241363

FromKeith Bainbridge <keithrbaugroups@gmail.com>
Date2021-10-16 06:10 +0200
Message-ID<D8Jbb-2nU-1@gated-at.bofh.it>
In reply to#241296
On 15/10/21 00:14, Greg Wooledge wrote:
> If for some reason you've forgotten the root password that you used
> during installation, or you've lost your membership in the sudo group,
> then you can add "init=/bin/bash" to the kernel parameters in GRUB,
> re-mount the root file system read/write, run the "passwd root" command
> to set a new root password, and then reboot again.


Good afternoon

My experience is that if you chose a root passwd at installation, sudo 
is NOT installed.


-- 
All the best

Keith Bainbridge

keithrbaugroups@gmail.com

[toc] | [prev] | [next] | [standalone]


#241382

FromGreg Wooledge <greg@wooledge.org>
Date2021-10-16 15:40 +0200
Message-ID<D8S4O-8h2-15@gated-at.bofh.it>
In reply to#241363
On Sat, Oct 16, 2021 at 03:00:28PM +1100, Keith Bainbridge wrote:
> 
> On 15/10/21 00:14, Greg Wooledge wrote:
> > If for some reason you've forgotten the root password that you used
> > during installation, or you've lost your membership in the sudo group,
> > then you can add "init=/bin/bash" to the kernel parameters in GRUB,
> > re-mount the root file system read/write, run the "passwd root" command
> > to set a new root password, and then reboot again.
> 
> 
> Good afternoon
> 
> My experience is that if you chose a root passwd at installation, sudo is
> NOT installed.

Correct.  I believe that in my earlier message, I said that sudo is
installed only if you choose to leave the root password blank.  If not,
then I at least implied it.

[toc] | [prev] | [next] | [standalone]


#241395

FromKeith Bainbridge <keithrbaugroups@gmail.com>
Date2021-10-17 09:00 +0200
Message-ID<D98jg-1KJ-1@gated-at.bofh.it>
In reply to#241382
On 17/10/21 00:33, Greg Wooledge wrote:
> On Sat, Oct 16, 2021 at 03:00:28PM +1100, Keith Bainbridge wrote:
>>
>> On 15/10/21 00:14, Greg Wooledge wrote:
>>> If for some reason you've forgotten the root password that you used
>>> during installation, or you've lost your membership in the sudo group,
>>> then you can add "init=/bin/bash" to the kernel parameters in GRUB,
>>> re-mount the root file system read/write, run the "passwd root" command
>>> to set a new root password, and then reboot again.
>>
>>
>> Good afternoon
>>
>> My experience is that if you chose a root passwd at installation, sudo is
>> NOT installed.
> 
> Correct.  I believe that in my earlier message, I said that sudo is
> installed only if you choose to leave the root password blank.  If not,
> then I at least implied it.
> 

Yes you had said that.

Somebody had kind of countered your comments by saying something like 
'if you have lost access to sudo'  I just wanted re-enforce your your words

-- 
All the best

Keith Bainbridge

keithrbaugroups@gmail.com

[toc] | [prev] | [next] | [standalone]


#241297

FromPeter Ehlert <pb21a@sdi-baja.com>
Date2021-10-14 15:40 +0200
Message-ID<D897H-3lc-1@gated-at.bofh.it>
In reply to#241295
On 10/14/21 5:54 AM, Pierre Frenkiel wrote:
> hi
> After  a Debian install on my amd64 laptop, I'm faced to what looks like
> a beautiful dead lock:
> I wanted to set a root account, but that was refused because I'm not
> in /etc/sudoers, and to put me in this file, I need root privilege!
providing some Basic info about How you installed and which ISO you used 
would be useful.
whatever.

if you can open a terminal type in "su -" (lower case, no quote marks) 
and use your User password.

PS: in my opinion you should avoid creating a sudoers file unless you 
really know what you are doing. the defaults are very insecure.
> I suppose that there is a solution, but I couldn't find it.
> Any idea?
>
> best regards,

[toc] | [prev] | [next] | [standalone]


#241399 — security of debian default sudoers file (was: dead lock)

FromGregor Zattler <telegraph@gmx.net>
Date2021-10-17 11:50 +0200
Subjectsecurity of debian default sudoers file (was: dead lock)
Message-ID<D9aXM-3rN-23@gated-at.bofh.it>
In reply to#241297
Hi Peter,
* Peter Ehlert <pb21a@sdi-baja.com> [2021-10-14; 06:30]:
> PS: in my opinion you should avoid creating a sudoers file unless you
> really know what you are doing. the defaults are very insecure.

Could you please elaborate on this, or provide a pointer?

Thanks; Gregor
--
 -... --- .-. . -.. ..--.. ...-.-

[toc] | [prev] | [next] | [standalone]


#241400 — Re: security of debian default sudoers file (was: dead lock)

FromKeith Bainbridge <keithrbaugroups@gmail.com>
Date2021-10-17 12:20 +0200
SubjectRe: security of debian default sudoers file (was: dead lock)
Message-ID<D9bqN-3QT-1@gated-at.bofh.it>
In reply to#241399
On 17/10/21 20:41, Gregor Zattler wrote:
>> PS: in my opinion you should avoid creating a sudoers file unless you
>> really know what you are doing. the defaults are very insecure.


So force sudo to use the root passwd.

After you ensure your root passwd works, simply add the line:

Defaults	rootpw

to /etc/sudoers.

You should need a fresh terminal to test this.




-- 
All the best

Keith Bainbridge

keithrbaugroups@gmail.com

[toc] | [prev] | [next] | [standalone]


#241300

FromStanislav Vlasov <stanislav.v.v@gmail.com>
Date2021-10-14 16:30 +0200
Message-ID<D89U6-3Rx-5@gated-at.bofh.it>
In reply to#241295
2021-10-14 17:54 GMT+05:00, Pierre Frenkiel <pierre.frenkiel@gmail.com>:
> hi
> After  a Debian install on my amd64 laptop, I'm faced to what looks like
> a beautiful dead lock:
> I wanted to set a root account, but that was refused because I'm not
> in /etc/sudoers, and to put me in this file, I need root privilege!
> I suppose that there is a solution, but I couldn't find it.
> Any idea?

My standard actions in such situations (unknown root password + no sudo rights):
A) boot from livecd, mount root partition into /mnt, chroot /mnt,
passwd, umount /mnt, reboot from hdd.
or
B) at boot add line to kernel parameters:
init=/bin/sh

after boot at prompt:

mount / -o remount,rw
passwd   # change root password
sync; sync
mount / -o remount,ro

and reboot (may be via reset button or power switch)

-- 
Stanislav

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web