Sponsored Content
Full Discussion: sudoers syntax
Top Forums UNIX for Advanced & Expert Users sudoers syntax Post 70311 by chuckuykendall on Wednesday 27th of April 2005 11:48:52 AM
Old 04-27-2005
sudoers syntax

I'm stuck with a dilemma. I am trying to control userid's access to the su command in such a way that he will not be able to su to root (su, su -, su root, su - root) but he will be able to su to any other user. I have tried the following syntax:

Code:
userid  ALL=/usr/bin/su ?*, !/usr/bin/su *root*

This catches "su", "su root", and "su - root", but not "su -". I've also tried the follow syntax:

Code:
Cmnd_Alias  SU_TO_ROOT = /usr/bin/su, /usr/bin/su -, /usr/bin/su *root*, /usr/bin/su - *root*
userid  ALL=ALL, !SU_TO_ROOT

This catches all four types of su'ing to root but it also catches all other su attempts, which I would like to leave open. Any suggestions?
 

10 More Discussions You Might Find Interesting

1. Linux

sudoers file

Hi, I have edited 'sudoers' file to allow 'cads' user shutdown the system without providing a password. Can someone tell me what's wrong with my file? It's not working when I 'sudo SHUTDOWN' command: sudo: SHUTDOWN: command not found Thanks a lot! # Host alias specification... (4 Replies)
Discussion started by: whatisthis
4 Replies

2. UNIX for Dummies Questions & Answers

sudoers on HP 11.11

Having a "running low on coffee" moment here & need help. On HP 11.11 where is the sudoers file located; I looked every place I could think of and don't see it. Thanks in advance:confused: (2 Replies)
Discussion started by: dhlopomo
2 Replies

3. Solaris

sudoers and sudo

Hi, on solaris 10, I have two users : user1 and user2 I want to create User_Alias and Cmnd_Alias to allow them to execute a command without prompting for sudo password. command I want these users should be able to run is '/usr/bin/su - abcd' . Also user1 and 2 need not type the 'abcd'... (6 Replies)
Discussion started by: upengan78
6 Replies

4. UNIX for Advanced & Expert Users

Usernames in Sudoers have #

We have users that have a # in their username. Sudo is working on some servers and not others. I have narrowed it down to the # in their username. Any suggestions or ideas why it is working on 1 server but not another. Server not working is - Solaris 10 patch level 138888-01 Server working is ... (1 Reply)
Discussion started by: Gibby13
1 Replies

5. UNIX for Dummies Questions & Answers

sudoers

i just installed/configured apache2.0 on my own aix5.3 mini server. i can start/stop apache by root, but i want to start it under my login id(admin) instead. i need to execute this command: /usr/bin/sudo /usr/IBM/HTTPServer/bin/apachectl stop/start. (5 Replies)
Discussion started by: tjmannonline
5 Replies

6. Solaris

sudoers

this is for the first time i am going to use sudoers i want know how to create sudoers and giving privileges for that users thanks in advance dinu (6 Replies)
Discussion started by: dinu
6 Replies

7. Solaris

sudoers

what is the configuration file for sudo? can we edit it as like other file or will it create any adverse effect on editing that file? thanks in advance dinu (1 Reply)
Discussion started by: dinu
1 Replies

8. UNIX for Dummies Questions & Answers

Help with Sudoers file

Hi using Solaris 10. trying to update /etc/sudoers file I need to add all the fist level operation team. This is what I have but it doesn't seem to work. Please help.Error message sudo su - >>> sudoers file: parse error, line 9 <<< >>> sudoers file: parse error, line 9 <<< ... (2 Replies)
Discussion started by: samnyc
2 Replies

9. Solaris

Sudoers

Having a bit of a discussion with a software vendor about this. Can anyone confirm my understanding? /etc/sudoers file example:- user1 server1 = NOPASSWD:/usr/bin/ls -l user1 server1 = NOPASSWD:/usr/bin/file But then the following command fails (logged in on server 1 as user1) because... (2 Replies)
Discussion started by: psychocandy
2 Replies

10. Shell Programming and Scripting

Syntax for sudoers file for mv command

Hi, On one of Solaris 10 server, apache service is running. Due to audit requirement, its error_log grows bigger and we are required to keep that. Sometimes it grows more than 200GB and fills up file-system. Purpose is, if error_log touches 10GB, apache service should stop, error_log should... (7 Replies)
Discussion started by: ron323232
7 Replies
chroot(1M)																chroot(1M)

NAME
chroot - change root directory for a command SYNOPSIS
newroot command DESCRIPTION
The command executes command relative to the newroot. The meaning of any initial slashes in path names is changed for command and any of its children to newroot. Furthermore, the initial working directory is newroot. Note that command suffixes that affect input or output for the command use the original root, not the new root. For example, the command: locates file relative to the original root, not the new one. The command variable includes both the command name and any arguments. The new root path name is always relative to the current root. Even if a is currently in effect, the newroot argument is relative to the current root of the running process. This command is restricted to users with appropriate privileges. EXTERNAL INFLUENCES
International Code Set Support Single- and multibyte character code sets are supported. WARNINGS
command cannot be in a shell script. Exercise extreme caution when referring to special files in the new root file system. does not search the environment variable for the location of command, so the absolute path name of command must be given. When using to establish a new environment, all absolute path name references to the file system are lost, rendering shared libraries inac- cessible. If continued access to shared libraries is needed for correct operation, the shared libraries and the dynamic loader be copied into the new root environment. SEE ALSO
chdir(2), chroot(2). STANDARDS CONFORMANCE
chroot(1M)
All times are GMT -4. The time now is 06:10 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy