sudo Configuration
Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x
sudo allows regular users to execute commands as another user (typically root) without knowing the root password. Properly configuring sudo is a critical aspect of server security management.
What You Will Learn
Section titled “What You Will Learn”- How sudo works and basic usage
- Safely editing the sudoers file with
visudo - sudoers file syntax
- Configuring sudo privileges for users and groups
- NOPASSWD configuration
- sudo log auditing
- The wheel group on EL systems
Prerequisites
Section titled “Prerequisites”- A system with EL 9.x installed
- Currently have
sudoprivileges or can log in as root - Familiarity with the basics of User and Group Management
sudo Basics
Section titled “sudo Basics”How sudo Works
Section titled “How sudo Works”When you execute sudo <command>:
- The system checks the
/etc/sudoersfile to verify whether the current user has permission - The user is prompted to enter their own password (not the root password)
- After successful verification, the command is executed as the target user (root by default)
- The action is recorded in the system log
$ sudo systemctl restart nginx[sudo] password for admin:$ sudo -u postgres psql$ sudo -lExample output:
Matching Defaults entries for admin on myserver: !visiblepw, always_set_home, match_group_by_gid, always_query_group_plugin, env_reset, env_keep="COLORS DISPLAY HOSTNAME HISTSIZE KDEDIR LS_COLORS", secure_path=/sbin:/bin:/usr/sbin:/usr/bin
User admin may run the following commands on myserver: (ALL) ALLThe wheel Group on EL Systems
Section titled “The wheel Group on EL Systems”On EL systems, the wheel group is the default administrator group. Users belonging to the wheel group have full sudo privileges.
$ getent group wheelwheel:x:10:admin$ sudo usermod -aG wheel newadminThis is the default wheel group configuration in /etc/sudoers:
$ sudo grep wheel /etc/sudoers## Allows people in group wheel to run all commands%wheel ALL=(ALL) ALLEditing sudoers with visudo
Section titled “Editing sudoers with visudo”The visudo command automatically checks for syntax errors when saving:
$ sudo visudoIf you want to use a different editor:
$ sudo EDITOR=vim visudoUsing the /etc/sudoers.d/ Directory
Section titled “Using the /etc/sudoers.d/ Directory”It is recommended to place custom configurations in the /etc/sudoers.d/ directory rather than modifying the main /etc/sudoers file directly:
$ sudo visudo -f /etc/sudoers.d/custom-rulesConfirm that the main file includes a reference to this directory (EL 9 includes it by default):
$ sudo grep "includedir" /etc/sudoers#includedir /etc/sudoers.dsudoers Syntax Explained
Section titled “sudoers Syntax Explained”Basic Format
Section titled “Basic Format”user host=(target-user:target-group) commandPart descriptions:
| Part | Description |
|---|---|
| User | The authorized username; prefix group names with % |
| Host | The host this rule applies to; ALL means all hosts |
| Target user | The user that can be switched to; ALL means all users |
| Target group | The group that can be switched to (optional) |
| Command | The commands allowed; ALL means all commands |
Common Configuration Examples
Section titled “Common Configuration Examples”deploy ALL=(ALL) ALL%developers ALL=(ALL) ALLwebadmin ALL=(ALL) /usr/bin/systemctl restart nginx, /usr/bin/systemctl reload nginxdbadmin ALL=(postgres) ALLoperator ALL=(ALL) ALL, !/usr/bin/su, !/usr/bin/passwd rootCommand Aliases
Section titled “Command Aliases”When multiple users need the same privileges, aliases can simplify the configuration:
Cmnd_Alias WEB_CMDS = /usr/bin/systemctl restart nginx, \ /usr/bin/systemctl reload nginx, \ /usr/bin/systemctl status nginx
Cmnd_Alias PKG_CMDS = /usr/bin/dnf install *, \ /usr/bin/dnf update *, \ /usr/bin/dnf remove *webadmin ALL=(ALL) WEB_CMDSpkgadmin ALL=(ALL) PKG_CMDSYou can also define user aliases and host aliases:
User_Alias WEBTEAM = zhangsan, lisi, wangwuWEBTEAM ALL=(ALL) WEB_CMDSNOPASSWD Configuration
Section titled “NOPASSWD Configuration”By default, using sudo requires the user to enter their own password. You can configure password-free execution:
deploy ALL=(ALL) NOPASSWD: ALLmonitor ALL=(ALL) NOPASSWD: /usr/bin/systemctl status *, /usr/bin/journalctl%wheel ALL=(ALL) NOPASSWD: ALLMixing PASSWD and NOPASSWD
Section titled “Mixing PASSWD and NOPASSWD”operator ALL=(ALL) NOPASSWD: /usr/bin/systemctl status *, PASSWD: /usr/bin/systemctl restart *sudo Log Auditing
Section titled “sudo Log Auditing”All sudo operations are recorded in the system log, which is essential for security auditing.
$ sudo journalctl -u sudo$ sudo grep sudo /var/log/secureExample output:
Mar 24 14:30:22 myserver sudo: admin : TTY=pts/0 ; PWD=/home/admin ; USER=root ; COMMAND=/usr/bin/systemctl restart nginxConfigure Detailed Logging
Section titled “Configure Detailed Logging”You can configure additional logging options in sudoers:
$ sudo visudo -f /etc/sudoers.d/loggingDefaults log_input, log_outputDefaults logfile="/var/log/sudo.log"Defaults iolog_dir="/var/log/sudo-io/%{seq}"Practical Example: Configuring Multi-Level Privileges
Section titled “Practical Example: Configuring Multi-Level Privileges”The following example demonstrates how to configure different sudo privileges for different roles.
-
Create the role configuration file
Create a custom sudoers file $ sudo visudo -f /etc/sudoers.d/team-roles -
Define command aliases
# Service management commandsCmnd_Alias SVC_CMDS = /usr/bin/systemctl start *, \/usr/bin/systemctl stop *, \/usr/bin/systemctl restart *, \/usr/bin/systemctl reload *, \/usr/bin/systemctl status *# Read-only monitoring commandsCmnd_Alias MON_CMDS = /usr/bin/systemctl status *, \/usr/bin/journalctl *, \/usr/bin/top, \/usr/bin/htop, \/usr/bin/ss, \/usr/bin/df, \/usr/bin/free -
Assign privileges
# Operations staff: full service management privileges%ops ALL=(ALL) SVC_CMDS# Monitoring staff: read-only privileges, no password required%monitors ALL=(ALL) NOPASSWD: MON_CMDS# Deployment account: full privileges, no passworddeploy ALL=(ALL) NOPASSWD: ALL -
Create the corresponding groups and add users
Create groups and add users $ sudo groupadd ops$ sudo groupadd monitors$ sudo usermod -aG ops zhangsan$ sudo usermod -aG monitors lisi -
Verify the configuration
Verify zhangsan's privileges $ sudo -U zhangsan sudo -l
Common sudo Options
Section titled “Common sudo Options”| Command | Description |
|---|---|
sudo <command> | Execute a command as root |
sudo -u <user> <command> | Execute a command as a specified user |
sudo -l | List the current user’s sudo privileges |
sudo -U <user> -l | List a specified user’s sudo privileges (requires root) |
sudo -i | Switch to root’s login shell |
sudo -s | Start a shell as root (without switching environment) |
sudo -k | Clear the sudo password cache |
sudo -v | Refresh the password cache timeout |
Common Issues
Section titled “Common Issues””xxx is not in the sudoers file”
Section titled “”xxx is not in the sudoers file””The user does not have sudo privileges. Add the user to the wheel group as root:
$ su -# usermod -aG wheel username# exit”syntax error” Prevents sudo from Working
Section titled “”syntax error” Prevents sudo from Working”If you incorrectly edited /etc/sudoers directly and introduced a syntax error:
Method 1: If you have another user with sudo privileges or can log in as root:
$ su -# visudoMethod 2: If you cannot log in as root, you will need to enter rescue mode.
How to Adjust the sudo Password Cache Duration
Section titled “How to Adjust the sudo Password Cache Duration”$ sudo visudo -f /etc/sudoers.d/timeoutDefaults timestamp_timeout=15Set to 0 to require a password every time. Set to -1 to never expire (not recommended).
How to Use sudo in Scripts
Section titled “How to Use sudo in Scripts”For automated scripts, it is recommended to configure NOPASSWD privileges for the script-executing user (limited to specific commands) to avoid the script hanging at a password prompt.
deploy ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart myapp, /usr/bin/dnf update myappFurther Reading
Section titled “Further Reading”- User and Group Management — Creating and managing users and groups
- File Permissions and ACLs — File-level permission control
- SSH Security Configuration — Remote access security
man sudo/man sudoers— Complete reference manuals