Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #198352 > unrolled thread

As seen above: use of su vs sudo

Started byMartin Drescher <keine-eile@online.de>
First post2018-08-07 12:00 +0200
Last post2018-08-07 18:30 +0200
Articles 20 on this page of 52 — 21 participants

Back to article view | Back to linux.debian.user


Contents

  As seen above: use of su vs sudo Martin Drescher <keine-eile@online.de> - 2018-08-07 12:00 +0200
    Re: As seen above: use of su vs sudo Joe <joe@jretrading.com> - 2018-08-07 12:50 +0200
      Re: As seen above: use of su vs sudo Jonathan Dowland <jmtd@debian.org> - 2018-08-07 13:20 +0200
        Re: As seen above: use of su vs sudo Martin Drescher <keine-eile@online.de> - 2018-08-07 13:30 +0200
          Re: As seen above: use of su vs sudo David Wright <deblis@lionunicorn.co.uk> - 2018-08-07 17:20 +0200
            Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 17:40 +0200
              Re: As seen above: use of su vs sudo Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2018-08-07 18:20 +0200
        Re: As seen above: use of su vs sudo Joe <joe@jretrading.com> - 2018-08-07 14:10 +0200
          Re: As seen above: use of su vs sudo likcoras <likcoras@riseup.net> - 2018-08-07 14:40 +0200
      Re: As seen above: use of su vs sudo likcoras <likcoras@riseup.net> - 2018-08-07 14:00 +0200
    Re: As seen above: use of su vs sudo Richard Owlett <rowlett@cloud85.net> - 2018-08-07 13:00 +0200
    Re: As seen above: use of su vs sudo Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-08-07 13:20 +0200
      Re: As seen above: use of su vs sudo James Allsopp <jamesaallsopp@googlemail.com> - 2018-08-07 13:30 +0200
        Re: As seen above: use of su vs sudo Curt <curty@free.fr> - 2018-08-07 13:50 +0200
          Re: As seen above: use of su vs sudo Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-08-07 14:30 +0200
            Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 14:30 +0200
          Re: As seen above: use of su vs sudo Jonathan Dowland <jmtd@debian.org> - 2018-08-07 15:20 +0200
            Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 15:50 +0200
        Re: As seen above: use of su vs sudo <tomas@tuxteam.de> - 2018-08-07 14:20 +0200
        Re: As seen above: use of su vs sudo Dave Sherohman <dave@sherohman.org> - 2018-08-07 15:30 +0200
      Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 13:40 +0200
        Re: As seen above: use of su vs sudo Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-08-07 14:30 +0200
    Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 13:30 +0200
      Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 13:50 +0200
        Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 14:10 +0200
          Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 14:30 +0200
            Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 15:00 +0200
              Re: As seen above: use of su vs sudo Nicolas George <george@nsup.org> - 2018-08-07 15:10 +0200
                Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 15:30 +0200
                  Re: As seen above: use of su vs sudo Nicolas George <george@nsup.org> - 2018-08-07 15:40 +0200
                    Re: As seen above: use of su vs sudo David Wright <deblis@lionunicorn.co.uk> - 2018-08-07 18:20 +0200
                      Re: As seen above: use of su vs sudo Nicolas George <george@nsup.org> - 2018-08-07 18:40 +0200
                        Re: As seen above: use of su vs sudo Greg Wooledge <wooledg@eeg.ccf.org> - 2018-08-07 18:50 +0200
                      Re: As seen above: use of su vs sudo Michael Stone <mstone@debian.org> - 2018-08-07 19:10 +0200
                        Re: As seen above: use of su vs sudo Curt <curty@free.fr> - 2018-08-07 20:10 +0200
                          Re: As seen above: use of su vs sudo Nicolas George <george@nsup.org> - 2018-08-07 20:10 +0200
                            Re: As seen above: use of su vs sudo Curt <curty@free.fr> - 2018-08-07 20:20 +0200
                          Re: As seen above: use of su vs sudo Michael Stone <mstone@debian.org> - 2018-08-07 20:50 +0200
              Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 15:10 +0200
                Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 15:30 +0200
                  Re: As seen above: use of su vs sudo Michael Stone <mstone@debian.org> - 2018-08-07 15:50 +0200
                  Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 15:50 +0200
              Re: As seen above: use of su vs sudo Nemeth Gyorgy <friczy@freemail.hu> - 2018-08-07 21:10 +0200
                Re: As seen above: use of su vs sudo Gene Heskett <gheskett@shentel.net> - 2018-08-07 22:10 +0200
            Re: As seen above: use of su vs sudo Michael Stone <mstone@debian.org> - 2018-08-07 15:20 +0200
            Re: As seen above: use of su vs sudo Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-08-07 16:10 +0200
          Re: As seen above: use of su vs sudo Dave Sherohman <dave@sherohman.org> - 2018-08-07 15:30 +0200
            Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 15:40 +0200
          Re: As seen above: use of su vs sudo David Wright <deblis@lionunicorn.co.uk> - 2018-08-07 18:10 +0200
    Re: As seen above: use of su vs sudo Eike Lantzsch <zp6cge@gmx.net> - 2018-08-07 14:30 +0200
    Re: As seen above: use of su vs sudo mick crane <mick.crane@gmail.com> - 2018-08-07 16:00 +0200
    Re: As seen above: use of su vs sudo mick crane <mick.crane@gmail.com> - 2018-08-07 18:30 +0200

Page 1 of 3  [1] 2 3  Next page →


#198352 — As seen above: use of su vs sudo

FromMartin Drescher <keine-eile@online.de>
Date2018-08-07 12:00 +0200
SubjectAs seen above: use of su vs sudo
Message-ID<wk6Wt-7qN-1@gated-at.bofh.it>
Hi members,

I'm a little... lets say thoughtful, about the use of 'su' discussed at some points in this list.
I have a strong opinion about su, which is, avoid it whenever it is possible and use 'sudo' instead. This is the case in close to a 100% in all cases I can think of.
This opinion is based on how both programs work and deal with pam and environmental variables. Not to forget: You will not need to share (or in my case, not even set, but lock that account) a root password.

And I'm curious why Debian still prefers the use of su over sudo?


Martin.

[toc] | [next] | [standalone]


#198356

FromJoe <joe@jretrading.com>
Date2018-08-07 12:50 +0200
Message-ID<wk7IR-7Wz-1@gated-at.bofh.it>
In reply to#198352
On Tue, 7 Aug 2018 11:58:48 +0200
Martin Drescher <keine-eile@online.de> wrote:

> Hi members,
> 
> I'm a little... lets say thoughtful, about the use of 'su' discussed
> at some points in this list. I have a strong opinion about su, which
> is, avoid it whenever it is possible and use 'sudo' instead. This is
> the case in close to a 100% in all cases I can think of. This opinion
> is based on how both programs work and deal with pam and
> environmental variables. Not to forget: You will not need to share
> (or in my case, not even set, but lock that account) a root password.
> 
> And I'm curious why Debian still prefers the use of su over sudo?

Why, I don't know, but the last time I installed stable, sudo was not
installed by default, and never has been in my experience. I always add
sudo and mc immediately after an installation.

Now I don't recall the details offhand, but there are some things sudo
cannot do, I think involving file permissions. The only time I use su
is when sudo doesn't do the job, which may be about once a year.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#198364

FromJonathan Dowland <jmtd@debian.org>
Date2018-08-07 13:20 +0200
Message-ID<wk8bT-8mI-11@gated-at.bofh.it>
In reply to#198356
On Tue, Aug 07, 2018 at 11:40:29AM +0100, Joe wrote:
>Why, I don't know, but the last time I installed stable, sudo was not
>installed by default, and never has been in my experience. I always add
>sudo and mc immediately after an installation.

If you set a root password in d-i (as it asks you to), it doesn't
install sudo. If you try to set a blank root password, it locks the root
account, installs sudo and sets up the user you created with sudo
access.

-- 

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland
⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net
⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#198366

FromMartin Drescher <keine-eile@online.de>
Date2018-08-07 13:30 +0200
Message-ID<wk8lz-8q5-1@gated-at.bofh.it>
In reply to#198364
That

> If you set a root password in d-i (as it asks you to), it doesn't
> install sudo. If you try to set a blank root password, it locks the root
> account, installs sudo and sets up the user you created with sudo
> access.

is new to me, I never knew! And I think it is good approach. Does one actually get pointed to this during install?
 

[toc] | [prev] | [next] | [standalone]


#198412

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2018-08-07 17:20 +0200
Message-ID<wkbWa-2hi-7@gated-at.bofh.it>
In reply to#198366
On Tue 07 Aug 2018 at 13:23:06 (+0200), Martin Drescher wrote:
> That
> 
> > If you set a root password in d-i (as it asks you to), it doesn't
> > install sudo. If you try to set a blank root password, it locks the root
> > account, installs sudo and sets up the user you created with sudo
> > access.
> 
> is new to me, I never knew! And I think it is good approach.
> Does one actually get pointed to this during install?

      ┌───────────────────┤ [?] Set up users and passwords ├────────────────────┐       
      │                                                                         │       
      │ If you choose not to allow root to log in, then a user account will be  │       
      │ created and given the power to become root using the 'sudo' command.    │       
      │                                                                         │       
      │ Allow login as root?                                                    │       
      │                                                                         │       
      │     <Go Back>                                         <Yes>    <No>     │       
      │                                                                         │       
      └─────────────────────────────────────────────────────────────────────────┘       

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#198413

FromMartin <keine-eile@online.de>
Date2018-08-07 17:40 +0200
Message-ID<wkcfv-2nX-1@gated-at.bofh.it>
In reply to#198412
[...]
>>
>> is new to me, I never knew! And I think it is good approach.
>> Does one actually get pointed to this during install?
> 
>       ┌───────────────────┤ [?] Set up users and passwords ├────────────────────┐       
>       │                                                                         │       
>       │ If you choose not to allow root to log in, then a user account will be  │       
>       │ created and given the power to become root using the 'sudo' command.    │       
>       │                                                                         │       
>       │ Allow login as root?                                                    │       
>       │                                                                         │       
>       │     <Go Back>                                         <Yes>    <No>     │       
>       │                                                                         │       
>       └─────────────────────────────────────────────────────────────────────────┘       
> 
> Cheers,
> David.
> 

How cool is that :-)
Actually, I mostly use the graphical installer for manual install. I just checked: This dialogue is 10 lines long. I usually stooped reading after "You need do set a password for 'root'...".


Cheers to you!

[toc] | [prev] | [next] | [standalone]


#198416

FromJoe Pfeiffer <pfeiffer@cs.nmsu.edu>
Date2018-08-07 18:20 +0200
Message-ID<wkcSd-2RJ-5@gated-at.bofh.it>
In reply to#198413
Martin <keine-eile@online.de> writes:

> [...]
>>>
>>> is new to me, I never knew! And I think it is good approach.
>>> Does one actually get pointed to this during install?
>> 
>>       ┌───────────────────┤ [?] Set up users and passwords ├────────────────────┐       
>>       │                                                                         │       
>>       │ If you choose not to allow root to log in, then a user account will be  │       
>>       │ created and given the power to become root using the 'sudo' command.    │       
>>       │                                                                         │       
>>       │ Allow login as root?                                                    │       
>>       │                                                                         │       
>>       │     <Go Back>                                         <Yes>    <No>     │       
>>       │                                                                         │       
>>       └─────────────────────────────────────────────────────────────────────────┘       
>> 
>> Cheers,
>> David.
>> 
>
> How cool is that :-)
> Actually, I mostly use the graphical installer for manual install. I
> just checked: This dialogue is 10 lines long. I usually stooped
> reading after "You need do set a password for 'root'...".

Though it seems like installing sudo and asking whether the "first user"
should be in sudoers would be a better thing to do even if root can log
in.

[toc] | [prev] | [next] | [standalone]


#198377

FromJoe <joe@jretrading.com>
Date2018-08-07 14:10 +0200
Message-ID<wk8Yh-se-5@gated-at.bofh.it>
In reply to#198364
On Tue, 7 Aug 2018 12:11:50 +0100
Jonathan Dowland <jmtd@debian.org> wrote:

> On Tue, Aug 07, 2018 at 11:40:29AM +0100, Joe wrote:
> >Why, I don't know, but the last time I installed stable, sudo was not
> >installed by default, and never has been in my experience. I always
> >add sudo and mc immediately after an installation.  
> 
> If you set a root password in d-i (as it asks you to), it doesn't
> install sudo. If you try to set a blank root password, it locks the
> root account, installs sudo and sets up the user you created with sudo
> access.
> 

OK, I've never tried that. I always want the option of connecting a
monitor and actually logging in as root, just in case of
difficulties. I believe that some boot problems are not solveable
without being able to provide a root password, long before the
operating system can provide su or sudo.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#198391

Fromlikcoras <likcoras@riseup.net>
Date2018-08-07 14:40 +0200
Message-ID<wk9rj-CX-1@gated-at.bofh.it>
In reply to#198377
On 08/07/2018 09:06 PM, Joe wrote:
> On Tue, 7 Aug 2018 12:11:50 +0100
> Jonathan Dowland <jmtd@debian.org> wrote:
>> If you set a root password in d-i (as it asks you to), it doesn't
>> install sudo. If you try to set a blank root password, it locks the
>> root account, installs sudo and sets up the user you created with sudo
>> access.
>>
> 
> OK, I've never tried that. I always want the option of connecting a
> monitor and actually logging in as root, just in case of
> difficulties. I believe that some boot problems are not solveable
> without being able to provide a root password, long before the
> operating system can provide su or sudo.

In those truly catastrophic cases, you can set init=/bin/sh in the
bootloader kernel line, which will boot you into a root shell.

[toc] | [prev] | [next] | [standalone]


#198376

Fromlikcoras <likcoras@riseup.net>
Date2018-08-07 14:00 +0200
Message-ID<wk8OC-9c-3@gated-at.bofh.it>
In reply to#198356
On 08/07/2018 07:40 PM, Joe wrote:
> On Tue, 7 Aug 2018 11:58:48 +0200
> Why, I don't know, but the last time I installed stable, sudo was not
> installed by default, and never has been in my experience. I always add
> sudo and mc immediately after an installation.

It's installed if you choose to 'disallow login as root' during
installation, which then would prompt you to create a user that will
automatically be given sudo access (by being in the sudo group).

[toc] | [prev] | [next] | [standalone]


#198358

FromRichard Owlett <rowlett@cloud85.net>
Date2018-08-07 13:00 +0200
Message-ID<wk7Sy-7ZZ-7@gated-at.bofh.it>
In reply to#198352
On 08/07/2018 04:58 AM, Martin Drescher wrote:
> Hi members,
> 
> I'm a little... lets say thoughtful, about the use of 'su' discussed at some points in this list.

I don't recall that discussion. Can you give a link to the archives?

> I have a strong opinion about su, which is, avoid it whenever it is possible and use 'sudo' instead. This is the case in close to a 100% in all cases I can think of.
> This opinion is based on how both programs work and deal with pam and environmental variables. Not to forget: You will not need to share (or in my case, not even set, but lock that account) a root password.
> 
> And I'm curious why Debian still prefers the use of su over sudo?

I'm not sure that is Debian's position. Every time I see a topic 
requiring root privileges sudo is used.

For my personal environment and use pattern I prefer su.
My environment is a single laptop without physical LAN or internet 
connectivity. It is a single user system - I am the only person with 
physical access.

As to use pattern, if I need root privileges, I'm doing experimental 
system restructuring. The closest I come to using sudo is my use of 
Gparted and Synaptic.

[toc] | [prev] | [next] | [standalone]


#198361

FromStephan Seitz <stse+debian@fsing.rootsland.net>
Date2018-08-07 13:20 +0200
Message-ID<wk8bT-8mI-5@gated-at.bofh.it>
In reply to#198352

[Multipart message — attachments visible in raw view] — view raw

On Di, Aug 07, 2018 at 11:58:48 +0200, Martin Drescher wrote:
>And I'm curious why Debian still prefers the use of su over sudo?

I don’t know if Debian does, but the difference between su and sudo seems 
quite like to the difference between ssh logins with password and with 
keys. Both have advantages and disadvantages.

Shade and sweet water!
	
	Stephan

-- 
| Public Keys: http://fsing.rootsland.net/~stse/keys.html |

[toc] | [prev] | [next] | [standalone]


#198369

FromJames Allsopp <jamesaallsopp@googlemail.com>
Date2018-08-07 13:30 +0200
Message-ID<wk8lz-8q5-9@gated-at.bofh.it>
In reply to#198361

[Multipart message — attachments visible in raw view] — view raw

As far as I can see "su -" saves a lot of grief if you're the only admin on
a system. Tried sudo ing to a protected directory? Doesn't work. Tired of
entering your password every couple of minutes?

sudo does mean that the admin actions of a particular user are logged, but
unless you lock down what they can do, they can change/delete the logs
easily enough.

I think this just degenerates into a religious war. If it works for you,
and the people around you, great. If not use the other option.

On 7 August 2018 at 12:11, Stephan Seitz <stse+debian@fsing.rootsland.net>
wrote:

> On Di, Aug 07, 2018 at 11:58:48 +0200, Martin Drescher wrote:
>
>> And I'm curious why Debian still prefers the use of su over sudo?
>>
>
> I don’t know if Debian does, but the difference between su and sudo seems
> quite like to the difference between ssh logins with password and with
> keys. Both have advantages and disadvantages.
>
> Shade and sweet water!
>
>         Stephan
>
> --
> | Public Keys: http://fsing.rootsland.net/~stse/keys.html |
>

[toc] | [prev] | [next] | [standalone]


#198373

FromCurt <curty@free.fr>
Date2018-08-07 13:50 +0200
Message-ID<wk8EV-5t-11@gated-at.bofh.it>
In reply to#198369
On 2018-08-07, James Allsopp <jamesaallsopp@googlemail.com> wrote:
>
> sudo does mean that the admin actions of a particular user are logged, but
> unless you lock down what they can do, they can change/delete the logs
> easily enough.
>

But it seems the whole point of the thing in a multi-user environment is
that you can use a granular approach to permissions, so I suppose if you
didn't desire a particular user modifying the logs, while granting her
other administrative privileges, that would fall completely within the
purview of the philosophy and implementation of the soft that is 'sudo'.

I've never used it myself. I'm all by my lonesome on this machine. I've
been using 'su' from the very beginning (but maybe I should start or
will start whenever the future and the new 'su' arrives using 'su -').

-- 
Some years ago, when the images which this world affords first opened upon me,
when I felt the cheering warmth of summer and heard the rustling of the leaves
and the warbling of the birds, and these were all to me, I should have wept to
die; now it is my only consolation. --Mary Shelley, Frankenstein; or, The Modern Prometheus

[toc] | [prev] | [next] | [standalone]


#198389

FromStephan Seitz <stse+debian@fsing.rootsland.net>
Date2018-08-07 14:30 +0200
Message-ID<wk9hE-zx-11@gated-at.bofh.it>
In reply to#198373

[Multipart message — attachments visible in raw view] — view raw

On Di, Aug 07, 2018 at 11:46:55 +0000, Curt wrote:
>But it seems the whole point of the thing in a multi-user environment is
>that you can use a granular approach to permissions, so I suppose if you
>didn't desire a particular user modifying the logs, while granting her
>other administrative privileges, that would fall completely within the
>purview of the philosophy and implementation of the soft that is 'sudo'.

Exactly. At home I’m the only person using my computer, so I don’t need 
the sudo philosophy.

At work we’re using sudo (interestingly without asked password, so if you 
could login, you can do „sudo -i”), but there is no administrator 
difference. Everyone in our small group has always full administrator 
access.

Shade and sweet water!

	Stephan

-- 
| Public Keys: http://fsing.rootsland.net/~stse/keys.html |

[toc] | [prev] | [next] | [standalone]


#198390

FromMartin <keine-eile@online.de>
Date2018-08-07 14:30 +0200
Message-ID<wk9hE-zx-13@gated-at.bofh.it>
In reply to#198389
Am 07.08.2018 um 14:19 schrieb Stephan Seitz:
> On Di, Aug 07, 2018 at 11:46:55 +0000, Curt wrote:
>> But it seems the whole point of the thing in a multi-user environment is
>> that you can use a granular approach to permissions, so I suppose if you
>> didn't desire a particular user modifying the logs, while granting her
>> other administrative privileges, that would fall completely within the
>> purview of the philosophy and implementation of the soft that is 'sudo'.
> 
> Exactly. At home I’m the only person using my computer, so I don’t need the sudo philosophy.
> 
> At work we’re using sudo (interestingly without asked password, so if you could login, you can do „sudo -i”), but there is no administrator difference. Everyone in our small group has always full administrator access.

It's the NOPASSWD directive in sudoers.

> 
> Shade and sweet water!
> 
>     Stephan
> 

[toc] | [prev] | [next] | [standalone]


#198400

FromJonathan Dowland <jmtd@debian.org>
Date2018-08-07 15:20 +0200
Message-ID<wka43-16H-21@gated-at.bofh.it>
In reply to#198373
On Tue, Aug 07, 2018 at 11:46:55AM +0000, Curt wrote:
>I've never used it myself. I'm all by my lonesome on this machine. I've
>been using 'su' from the very beginning (but maybe I should start or
>will start whenever the future and the new 'su' arrives using 'su -').

I've long forgotten why, but I committed "sudo su -" to muscle memory
sometime in the last two decades, and I'm mildly amused to see I'm
escaping the coming su-pocalypse unscathed.

-- 

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland
⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net
⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.

[toc] | [prev] | [next] | [standalone]


#198407

FromMartin <keine-eile@online.de>
Date2018-08-07 15:50 +0200
Message-ID<wkax3-1hh-5@gated-at.bofh.it>
In reply to#198400
> I've long forgotten why, but I committed "sudo su -" to muscle memory

First, you execute sudo with target UID 0 (aka. root). 
While doing that, sudo does all the fancy things for you, like setting or unsetting environments (eg SUDO_COMMAND, SUDO_UID, SUDO_USER) and check, if you will be granted to run $ANY_COMMAND or may be /bin/su with that target UID 0.
Next, with UID 0, you run /bin/su in order, to gain a login shell. Now '/bin/su -' runs the login process stripping all the things set before off. Just to run /bin/sh at the end.

You could have run 'sudo -c /bin/sh'.
In reality, 'sudo -i [-u TARGET_USER]' is your friend. Always.

[toc] | [prev] | [next] | [standalone]


#198381

From<tomas@tuxteam.de>
Date2018-08-07 14:20 +0200
Message-ID<wk97X-vY-3@gated-at.bofh.it>
In reply to#198369
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, Aug 07, 2018 at 12:22:53PM +0100, James Allsopp wrote:
> As far as I can see "su -" saves a lot of grief if you're the only admin on
> a system. Tried sudo ing to a protected directory? Doesn't work. Tired of
> entering your password every couple of minutes?

There's "sudo -s" for that, as in "gimme a root shell".

> sudo does mean that the admin actions of a particular user are logged, but
> unless you lock down what they can do, they can change/delete the logs
> easily enough.

That's not the main point of sudo. Yes, you can control it in many
fine-grained ways, which is a boon if you want to give (somewhat
restricted) powers to e.g. a backup script.

> I think this just degenerates into a religious war [...]

This makes as much sense as having a religious war in the workshop
on whether a Phillips screwdriver is "better" than a circular saw.

Ever tried to tighten a Phillips screw with a circular saw?

Enjoy your tools. Get to know them, and pick. Me, I've never needed
su since I got the hang of sudo, but why would I want to force anyone
to do the same?

OTOH, I don't like the idea of a passwordless root (my dislike comes
from the first time I went with that and stood in front of a machine
with a broken root file system telling me to enter the root password
to fix things :-)

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAltpjB4ACgkQBcgs9XrR2kZv/gCggF3+9FcemzsJ0ISMrhFtf8eM
AzUAn0OPybYmMuq+Nd6z4LroDa04R0U+
=3TtR
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#198401

FromDave Sherohman <dave@sherohman.org>
Date2018-08-07 15:30 +0200
Message-ID<wkadH-1ac-5@gated-at.bofh.it>
In reply to#198369
On Tue, Aug 07, 2018 at 12:22:53PM +0100, James Allsopp wrote:
> As far as I can see "su -" saves a lot of grief if you're the only admin on
> a system. Tried sudo ing to a protected directory? Doesn't work.

Works fine for me:

dave$ sudo bash
[sudo] password for dave:
root# cd /some/protected/dir
root# 

> Tired of entering your password every couple of minutes?

Even without using sudo to start a shell, it (by default) remembers that
you've already authenticated recently and you only have to re-enter your
password if you go more than 15 minutes without running a sudo command.

-- 
Dave Sherohman

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web