Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #198352 > unrolled thread
| Started by | Martin Drescher <keine-eile@online.de> |
|---|---|
| First post | 2018-08-07 12:00 +0200 |
| Last post | 2018-08-07 18:30 +0200 |
| Articles | 20 on this page of 52 — 21 participants |
Back to article view | Back to linux.debian.user
As seen above: use of su vs sudo Martin Drescher <keine-eile@online.de> - 2018-08-07 12:00 +0200
Re: As seen above: use of su vs sudo Joe <joe@jretrading.com> - 2018-08-07 12:50 +0200
Re: As seen above: use of su vs sudo Jonathan Dowland <jmtd@debian.org> - 2018-08-07 13:20 +0200
Re: As seen above: use of su vs sudo Martin Drescher <keine-eile@online.de> - 2018-08-07 13:30 +0200
Re: As seen above: use of su vs sudo David Wright <deblis@lionunicorn.co.uk> - 2018-08-07 17:20 +0200
Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 17:40 +0200
Re: As seen above: use of su vs sudo Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2018-08-07 18:20 +0200
Re: As seen above: use of su vs sudo Joe <joe@jretrading.com> - 2018-08-07 14:10 +0200
Re: As seen above: use of su vs sudo likcoras <likcoras@riseup.net> - 2018-08-07 14:40 +0200
Re: As seen above: use of su vs sudo likcoras <likcoras@riseup.net> - 2018-08-07 14:00 +0200
Re: As seen above: use of su vs sudo Richard Owlett <rowlett@cloud85.net> - 2018-08-07 13:00 +0200
Re: As seen above: use of su vs sudo Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-08-07 13:20 +0200
Re: As seen above: use of su vs sudo James Allsopp <jamesaallsopp@googlemail.com> - 2018-08-07 13:30 +0200
Re: As seen above: use of su vs sudo Curt <curty@free.fr> - 2018-08-07 13:50 +0200
Re: As seen above: use of su vs sudo Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-08-07 14:30 +0200
Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 14:30 +0200
Re: As seen above: use of su vs sudo Jonathan Dowland <jmtd@debian.org> - 2018-08-07 15:20 +0200
Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 15:50 +0200
Re: As seen above: use of su vs sudo <tomas@tuxteam.de> - 2018-08-07 14:20 +0200
Re: As seen above: use of su vs sudo Dave Sherohman <dave@sherohman.org> - 2018-08-07 15:30 +0200
Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 13:40 +0200
Re: As seen above: use of su vs sudo Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-08-07 14:30 +0200
Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 13:30 +0200
Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 13:50 +0200
Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 14:10 +0200
Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 14:30 +0200
Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 15:00 +0200
Re: As seen above: use of su vs sudo Nicolas George <george@nsup.org> - 2018-08-07 15:10 +0200
Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 15:30 +0200
Re: As seen above: use of su vs sudo Nicolas George <george@nsup.org> - 2018-08-07 15:40 +0200
Re: As seen above: use of su vs sudo David Wright <deblis@lionunicorn.co.uk> - 2018-08-07 18:20 +0200
Re: As seen above: use of su vs sudo Nicolas George <george@nsup.org> - 2018-08-07 18:40 +0200
Re: As seen above: use of su vs sudo Greg Wooledge <wooledg@eeg.ccf.org> - 2018-08-07 18:50 +0200
Re: As seen above: use of su vs sudo Michael Stone <mstone@debian.org> - 2018-08-07 19:10 +0200
Re: As seen above: use of su vs sudo Curt <curty@free.fr> - 2018-08-07 20:10 +0200
Re: As seen above: use of su vs sudo Nicolas George <george@nsup.org> - 2018-08-07 20:10 +0200
Re: As seen above: use of su vs sudo Curt <curty@free.fr> - 2018-08-07 20:20 +0200
Re: As seen above: use of su vs sudo Michael Stone <mstone@debian.org> - 2018-08-07 20:50 +0200
Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 15:10 +0200
Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 15:30 +0200
Re: As seen above: use of su vs sudo Michael Stone <mstone@debian.org> - 2018-08-07 15:50 +0200
Re: As seen above: use of su vs sudo Martin <keine-eile@online.de> - 2018-08-07 15:50 +0200
Re: As seen above: use of su vs sudo Nemeth Gyorgy <friczy@freemail.hu> - 2018-08-07 21:10 +0200
Re: As seen above: use of su vs sudo Gene Heskett <gheskett@shentel.net> - 2018-08-07 22:10 +0200
Re: As seen above: use of su vs sudo Michael Stone <mstone@debian.org> - 2018-08-07 15:20 +0200
Re: As seen above: use of su vs sudo Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-08-07 16:10 +0200
Re: As seen above: use of su vs sudo Dave Sherohman <dave@sherohman.org> - 2018-08-07 15:30 +0200
Re: As seen above: use of su vs sudo The Wanderer <wanderer@fastmail.fm> - 2018-08-07 15:40 +0200
Re: As seen above: use of su vs sudo David Wright <deblis@lionunicorn.co.uk> - 2018-08-07 18:10 +0200
Re: As seen above: use of su vs sudo Eike Lantzsch <zp6cge@gmx.net> - 2018-08-07 14:30 +0200
Re: As seen above: use of su vs sudo mick crane <mick.crane@gmail.com> - 2018-08-07 16:00 +0200
Re: As seen above: use of su vs sudo mick crane <mick.crane@gmail.com> - 2018-08-07 18:30 +0200
Page 1 of 3 [1] 2 3 Next page →
| From | Martin Drescher <keine-eile@online.de> |
|---|---|
| Date | 2018-08-07 12:00 +0200 |
| Subject | As seen above: use of su vs sudo |
| Message-ID | <wk6Wt-7qN-1@gated-at.bofh.it> |
Hi members, I'm a little... lets say thoughtful, about the use of 'su' discussed at some points in this list. I have a strong opinion about su, which is, avoid it whenever it is possible and use 'sudo' instead. This is the case in close to a 100% in all cases I can think of. This opinion is based on how both programs work and deal with pam and environmental variables. Not to forget: You will not need to share (or in my case, not even set, but lock that account) a root password. And I'm curious why Debian still prefers the use of su over sudo? Martin.
[toc] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2018-08-07 12:50 +0200 |
| Message-ID | <wk7IR-7Wz-1@gated-at.bofh.it> |
| In reply to | #198352 |
On Tue, 7 Aug 2018 11:58:48 +0200 Martin Drescher <keine-eile@online.de> wrote: > Hi members, > > I'm a little... lets say thoughtful, about the use of 'su' discussed > at some points in this list. I have a strong opinion about su, which > is, avoid it whenever it is possible and use 'sudo' instead. This is > the case in close to a 100% in all cases I can think of. This opinion > is based on how both programs work and deal with pam and > environmental variables. Not to forget: You will not need to share > (or in my case, not even set, but lock that account) a root password. > > And I'm curious why Debian still prefers the use of su over sudo? Why, I don't know, but the last time I installed stable, sudo was not installed by default, and never has been in my experience. I always add sudo and mc immediately after an installation. Now I don't recall the details offhand, but there are some things sudo cannot do, I think involving file permissions. The only time I use su is when sudo doesn't do the job, which may be about once a year. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2018-08-07 13:20 +0200 |
| Message-ID | <wk8bT-8mI-11@gated-at.bofh.it> |
| In reply to | #198356 |
On Tue, Aug 07, 2018 at 11:40:29AM +0100, Joe wrote: >Why, I don't know, but the last time I installed stable, sudo was not >installed by default, and never has been in my experience. I always add >sudo and mc immediately after an installation. If you set a root password in d-i (as it asks you to), it doesn't install sudo. If you try to set a blank root password, it locks the root account, installs sudo and sets up the user you created with sudo access. -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland ⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net ⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
| From | Martin Drescher <keine-eile@online.de> |
|---|---|
| Date | 2018-08-07 13:30 +0200 |
| Message-ID | <wk8lz-8q5-1@gated-at.bofh.it> |
| In reply to | #198364 |
That > If you set a root password in d-i (as it asks you to), it doesn't > install sudo. If you try to set a blank root password, it locks the root > account, installs sudo and sets up the user you created with sudo > access. is new to me, I never knew! And I think it is good approach. Does one actually get pointed to this during install?
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2018-08-07 17:20 +0200 |
| Message-ID | <wkbWa-2hi-7@gated-at.bofh.it> |
| In reply to | #198366 |
On Tue 07 Aug 2018 at 13:23:06 (+0200), Martin Drescher wrote:
> That
>
> > If you set a root password in d-i (as it asks you to), it doesn't
> > install sudo. If you try to set a blank root password, it locks the root
> > account, installs sudo and sets up the user you created with sudo
> > access.
>
> is new to me, I never knew! And I think it is good approach.
> Does one actually get pointed to this during install?
┌───────────────────┤ [?] Set up users and passwords ├────────────────────┐
│ │
│ If you choose not to allow root to log in, then a user account will be │
│ created and given the power to become root using the 'sudo' command. │
│ │
│ Allow login as root? │
│ │
│ <Go Back> <Yes> <No> │
│ │
└─────────────────────────────────────────────────────────────────────────┘
Cheers,
David.
[toc] | [prev] | [next] | [standalone]
| From | Martin <keine-eile@online.de> |
|---|---|
| Date | 2018-08-07 17:40 +0200 |
| Message-ID | <wkcfv-2nX-1@gated-at.bofh.it> |
| In reply to | #198412 |
[...] >> >> is new to me, I never knew! And I think it is good approach. >> Does one actually get pointed to this during install? > > ┌───────────────────┤ [?] Set up users and passwords ├────────────────────┐ > │ │ > │ If you choose not to allow root to log in, then a user account will be │ > │ created and given the power to become root using the 'sudo' command. │ > │ │ > │ Allow login as root? │ > │ │ > │ <Go Back> <Yes> <No> │ > │ │ > └─────────────────────────────────────────────────────────────────────────┘ > > Cheers, > David. > How cool is that :-) Actually, I mostly use the graphical installer for manual install. I just checked: This dialogue is 10 lines long. I usually stooped reading after "You need do set a password for 'root'...". Cheers to you!
[toc] | [prev] | [next] | [standalone]
| From | Joe Pfeiffer <pfeiffer@cs.nmsu.edu> |
|---|---|
| Date | 2018-08-07 18:20 +0200 |
| Message-ID | <wkcSd-2RJ-5@gated-at.bofh.it> |
| In reply to | #198413 |
Martin <keine-eile@online.de> writes: > [...] >>> >>> is new to me, I never knew! And I think it is good approach. >>> Does one actually get pointed to this during install? >> >> ┌───────────────────┤ [?] Set up users and passwords ├────────────────────┐ >> │ │ >> │ If you choose not to allow root to log in, then a user account will be │ >> │ created and given the power to become root using the 'sudo' command. │ >> │ │ >> │ Allow login as root? │ >> │ │ >> │ <Go Back> <Yes> <No> │ >> │ │ >> └─────────────────────────────────────────────────────────────────────────┘ >> >> Cheers, >> David. >> > > How cool is that :-) > Actually, I mostly use the graphical installer for manual install. I > just checked: This dialogue is 10 lines long. I usually stooped > reading after "You need do set a password for 'root'...". Though it seems like installing sudo and asking whether the "first user" should be in sudoers would be a better thing to do even if root can log in.
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2018-08-07 14:10 +0200 |
| Message-ID | <wk8Yh-se-5@gated-at.bofh.it> |
| In reply to | #198364 |
On Tue, 7 Aug 2018 12:11:50 +0100 Jonathan Dowland <jmtd@debian.org> wrote: > On Tue, Aug 07, 2018 at 11:40:29AM +0100, Joe wrote: > >Why, I don't know, but the last time I installed stable, sudo was not > >installed by default, and never has been in my experience. I always > >add sudo and mc immediately after an installation. > > If you set a root password in d-i (as it asks you to), it doesn't > install sudo. If you try to set a blank root password, it locks the > root account, installs sudo and sets up the user you created with sudo > access. > OK, I've never tried that. I always want the option of connecting a monitor and actually logging in as root, just in case of difficulties. I believe that some boot problems are not solveable without being able to provide a root password, long before the operating system can provide su or sudo. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | likcoras <likcoras@riseup.net> |
|---|---|
| Date | 2018-08-07 14:40 +0200 |
| Message-ID | <wk9rj-CX-1@gated-at.bofh.it> |
| In reply to | #198377 |
On 08/07/2018 09:06 PM, Joe wrote: > On Tue, 7 Aug 2018 12:11:50 +0100 > Jonathan Dowland <jmtd@debian.org> wrote: >> If you set a root password in d-i (as it asks you to), it doesn't >> install sudo. If you try to set a blank root password, it locks the >> root account, installs sudo and sets up the user you created with sudo >> access. >> > > OK, I've never tried that. I always want the option of connecting a > monitor and actually logging in as root, just in case of > difficulties. I believe that some boot problems are not solveable > without being able to provide a root password, long before the > operating system can provide su or sudo. In those truly catastrophic cases, you can set init=/bin/sh in the bootloader kernel line, which will boot you into a root shell.
[toc] | [prev] | [next] | [standalone]
| From | likcoras <likcoras@riseup.net> |
|---|---|
| Date | 2018-08-07 14:00 +0200 |
| Message-ID | <wk8OC-9c-3@gated-at.bofh.it> |
| In reply to | #198356 |
On 08/07/2018 07:40 PM, Joe wrote: > On Tue, 7 Aug 2018 11:58:48 +0200 > Why, I don't know, but the last time I installed stable, sudo was not > installed by default, and never has been in my experience. I always add > sudo and mc immediately after an installation. It's installed if you choose to 'disallow login as root' during installation, which then would prompt you to create a user that will automatically be given sudo access (by being in the sudo group).
[toc] | [prev] | [next] | [standalone]
| From | Richard Owlett <rowlett@cloud85.net> |
|---|---|
| Date | 2018-08-07 13:00 +0200 |
| Message-ID | <wk7Sy-7ZZ-7@gated-at.bofh.it> |
| In reply to | #198352 |
On 08/07/2018 04:58 AM, Martin Drescher wrote: > Hi members, > > I'm a little... lets say thoughtful, about the use of 'su' discussed at some points in this list. I don't recall that discussion. Can you give a link to the archives? > I have a strong opinion about su, which is, avoid it whenever it is possible and use 'sudo' instead. This is the case in close to a 100% in all cases I can think of. > This opinion is based on how both programs work and deal with pam and environmental variables. Not to forget: You will not need to share (or in my case, not even set, but lock that account) a root password. > > And I'm curious why Debian still prefers the use of su over sudo? I'm not sure that is Debian's position. Every time I see a topic requiring root privileges sudo is used. For my personal environment and use pattern I prefer su. My environment is a single laptop without physical LAN or internet connectivity. It is a single user system - I am the only person with physical access. As to use pattern, if I need root privileges, I'm doing experimental system restructuring. The closest I come to using sudo is my use of Gparted and Synaptic.
[toc] | [prev] | [next] | [standalone]
| From | Stephan Seitz <stse+debian@fsing.rootsland.net> |
|---|---|
| Date | 2018-08-07 13:20 +0200 |
| Message-ID | <wk8bT-8mI-5@gated-at.bofh.it> |
| In reply to | #198352 |
[Multipart message — attachments visible in raw view] — view raw
On Di, Aug 07, 2018 at 11:58:48 +0200, Martin Drescher wrote: >And I'm curious why Debian still prefers the use of su over sudo? I don’t know if Debian does, but the difference between su and sudo seems quite like to the difference between ssh logins with password and with keys. Both have advantages and disadvantages. Shade and sweet water! Stephan -- | Public Keys: http://fsing.rootsland.net/~stse/keys.html |
[toc] | [prev] | [next] | [standalone]
| From | James Allsopp <jamesaallsopp@googlemail.com> |
|---|---|
| Date | 2018-08-07 13:30 +0200 |
| Message-ID | <wk8lz-8q5-9@gated-at.bofh.it> |
| In reply to | #198361 |
[Multipart message — attachments visible in raw view] — view raw
As far as I can see "su -" saves a lot of grief if you're the only admin on a system. Tried sudo ing to a protected directory? Doesn't work. Tired of entering your password every couple of minutes? sudo does mean that the admin actions of a particular user are logged, but unless you lock down what they can do, they can change/delete the logs easily enough. I think this just degenerates into a religious war. If it works for you, and the people around you, great. If not use the other option. On 7 August 2018 at 12:11, Stephan Seitz <stse+debian@fsing.rootsland.net> wrote: > On Di, Aug 07, 2018 at 11:58:48 +0200, Martin Drescher wrote: > >> And I'm curious why Debian still prefers the use of su over sudo? >> > > I don’t know if Debian does, but the difference between su and sudo seems > quite like to the difference between ssh logins with password and with > keys. Both have advantages and disadvantages. > > Shade and sweet water! > > Stephan > > -- > | Public Keys: http://fsing.rootsland.net/~stse/keys.html | >
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2018-08-07 13:50 +0200 |
| Message-ID | <wk8EV-5t-11@gated-at.bofh.it> |
| In reply to | #198369 |
On 2018-08-07, James Allsopp <jamesaallsopp@googlemail.com> wrote: > > sudo does mean that the admin actions of a particular user are logged, but > unless you lock down what they can do, they can change/delete the logs > easily enough. > But it seems the whole point of the thing in a multi-user environment is that you can use a granular approach to permissions, so I suppose if you didn't desire a particular user modifying the logs, while granting her other administrative privileges, that would fall completely within the purview of the philosophy and implementation of the soft that is 'sudo'. I've never used it myself. I'm all by my lonesome on this machine. I've been using 'su' from the very beginning (but maybe I should start or will start whenever the future and the new 'su' arrives using 'su -'). -- Some years ago, when the images which this world affords first opened upon me, when I felt the cheering warmth of summer and heard the rustling of the leaves and the warbling of the birds, and these were all to me, I should have wept to die; now it is my only consolation. --Mary Shelley, Frankenstein; or, The Modern Prometheus
[toc] | [prev] | [next] | [standalone]
| From | Stephan Seitz <stse+debian@fsing.rootsland.net> |
|---|---|
| Date | 2018-08-07 14:30 +0200 |
| Message-ID | <wk9hE-zx-11@gated-at.bofh.it> |
| In reply to | #198373 |
[Multipart message — attachments visible in raw view] — view raw
On Di, Aug 07, 2018 at 11:46:55 +0000, Curt wrote: >But it seems the whole point of the thing in a multi-user environment is >that you can use a granular approach to permissions, so I suppose if you >didn't desire a particular user modifying the logs, while granting her >other administrative privileges, that would fall completely within the >purview of the philosophy and implementation of the soft that is 'sudo'. Exactly. At home I’m the only person using my computer, so I don’t need the sudo philosophy. At work we’re using sudo (interestingly without asked password, so if you could login, you can do „sudo -i”), but there is no administrator difference. Everyone in our small group has always full administrator access. Shade and sweet water! Stephan -- | Public Keys: http://fsing.rootsland.net/~stse/keys.html |
[toc] | [prev] | [next] | [standalone]
| From | Martin <keine-eile@online.de> |
|---|---|
| Date | 2018-08-07 14:30 +0200 |
| Message-ID | <wk9hE-zx-13@gated-at.bofh.it> |
| In reply to | #198389 |
Am 07.08.2018 um 14:19 schrieb Stephan Seitz: > On Di, Aug 07, 2018 at 11:46:55 +0000, Curt wrote: >> But it seems the whole point of the thing in a multi-user environment is >> that you can use a granular approach to permissions, so I suppose if you >> didn't desire a particular user modifying the logs, while granting her >> other administrative privileges, that would fall completely within the >> purview of the philosophy and implementation of the soft that is 'sudo'. > > Exactly. At home I’m the only person using my computer, so I don’t need the sudo philosophy. > > At work we’re using sudo (interestingly without asked password, so if you could login, you can do „sudo -i”), but there is no administrator difference. Everyone in our small group has always full administrator access. It's the NOPASSWD directive in sudoers. > > Shade and sweet water! > > Stephan >
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2018-08-07 15:20 +0200 |
| Message-ID | <wka43-16H-21@gated-at.bofh.it> |
| In reply to | #198373 |
On Tue, Aug 07, 2018 at 11:46:55AM +0000, Curt wrote: >I've never used it myself. I'm all by my lonesome on this machine. I've >been using 'su' from the very beginning (but maybe I should start or >will start whenever the future and the new 'su' arrives using 'su -'). I've long forgotten why, but I committed "sudo su -" to muscle memory sometime in the last two decades, and I'm mildly amused to see I'm escaping the coming su-pocalypse unscathed. -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland ⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net ⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
| From | Martin <keine-eile@online.de> |
|---|---|
| Date | 2018-08-07 15:50 +0200 |
| Message-ID | <wkax3-1hh-5@gated-at.bofh.it> |
| In reply to | #198400 |
> I've long forgotten why, but I committed "sudo su -" to muscle memory First, you execute sudo with target UID 0 (aka. root). While doing that, sudo does all the fancy things for you, like setting or unsetting environments (eg SUDO_COMMAND, SUDO_UID, SUDO_USER) and check, if you will be granted to run $ANY_COMMAND or may be /bin/su with that target UID 0. Next, with UID 0, you run /bin/su in order, to gain a login shell. Now '/bin/su -' runs the login process stripping all the things set before off. Just to run /bin/sh at the end. You could have run 'sudo -c /bin/sh'. In reality, 'sudo -i [-u TARGET_USER]' is your friend. Always.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2018-08-07 14:20 +0200 |
| Message-ID | <wk97X-vY-3@gated-at.bofh.it> |
| In reply to | #198369 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, Aug 07, 2018 at 12:22:53PM +0100, James Allsopp wrote: > As far as I can see "su -" saves a lot of grief if you're the only admin on > a system. Tried sudo ing to a protected directory? Doesn't work. Tired of > entering your password every couple of minutes? There's "sudo -s" for that, as in "gimme a root shell". > sudo does mean that the admin actions of a particular user are logged, but > unless you lock down what they can do, they can change/delete the logs > easily enough. That's not the main point of sudo. Yes, you can control it in many fine-grained ways, which is a boon if you want to give (somewhat restricted) powers to e.g. a backup script. > I think this just degenerates into a religious war [...] This makes as much sense as having a religious war in the workshop on whether a Phillips screwdriver is "better" than a circular saw. Ever tried to tighten a Phillips screw with a circular saw? Enjoy your tools. Get to know them, and pick. Me, I've never needed su since I got the hang of sudo, but why would I want to force anyone to do the same? OTOH, I don't like the idea of a passwordless root (my dislike comes from the first time I went with that and stood in front of a machine with a broken root file system telling me to enter the root password to fix things :-) Cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAltpjB4ACgkQBcgs9XrR2kZv/gCggF3+9FcemzsJ0ISMrhFtf8eM AzUAn0OPybYmMuq+Nd6z4LroDa04R0U+ =3TtR -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Dave Sherohman <dave@sherohman.org> |
|---|---|
| Date | 2018-08-07 15:30 +0200 |
| Message-ID | <wkadH-1ac-5@gated-at.bofh.it> |
| In reply to | #198369 |
On Tue, Aug 07, 2018 at 12:22:53PM +0100, James Allsopp wrote: > As far as I can see "su -" saves a lot of grief if you're the only admin on > a system. Tried sudo ing to a protected directory? Doesn't work. Works fine for me: dave$ sudo bash [sudo] password for dave: root# cd /some/protected/dir root# > Tired of entering your password every couple of minutes? Even without using sudo to start a shell, it (by default) remembers that you've already authenticated recently and you only have to re-enter your password if you go more than 15 minutes without running a sudo command. -- Dave Sherohman
[toc] | [prev] | [next] | [standalone]
Page 1 of 3 [1] 2 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web