This guide provides an overview of the sudo command in Linux, explaining its purpose, how to install it if necessary, and how to use its various options to execute commands with elevated privileges.
The sudo command allows a permitted user to execute a command as the superuser (root) or another user, as specified by the security policy. It is a fundamental tool for managing administrative tasks while minimizing security risks.
- Examples: Ubuntu Desktop, Linux Mint, Fedora Workstation, openSUSE Leap.
- Characteristics:
sudois pre-installed and pre-configured for convenience.- An initial user is created and added to the
sudoorwheelgroup during installation. - The
/etc/sudoersfile is configured to allow users in thesudoorwheelgroup to run all commands withsudo. - Password prompts and timeouts are set for security.
- Examples: Ubuntu Server, Debian Server, CentOS, Red Hat Enterprise Linux (RHEL), Fedora Server.
- Characteristics:
sudois often not pre-installed or pre-configured.- Manual installation and configuration are required.
- Provides enhanced security and customization options.
rpm -qa | grep sudo
- If installed, you will see an output like
sudo-1.9.5p2-10.el9.x86_64.
For RPM-based distributions (e.g., RHEL, CentOS):
yum install sudo
For DEB-based distributions (e.g., Debian, Ubuntu):
apt-get install sudo
List all files provided by the sudo package:
rpm -ql sudo
View configuration files of sudo:
rpm -qc sudo
Sample Output:
/etc/dnf/protected.d/sudo.conf
/etc/pam.d/sudo
/etc/pam.d/sudo-i
/etc/sudo-ldap.conf
/etc/sudo.conf
/etc/sudoers
sudo [options] [command]
| Option | Description | Example | Explanation |
|---|---|---|---|
-l |
Lists allowed and forbidden commands for the user. | sudo -l |
Shows commands the user can execute with sudo as per the sudoers configuration. |
-u <user> |
Executes the command as a specified user (default: root). |
sudo -u john whoami |
Runs whoami as the user john. |
-g <group> |
Executes the command with a specified group. | sudo -g developers id |
Runs id with the group set to developers. |
-i |
Starts an interactive shell as the specified user (or root). |
sudo -i |
Opens a root shell with the environment of the root user. |
-s |
Starts a shell with the user's environment but with elevated privileges. | sudo -s |
Opens a shell with the original user's environment variables. |
-k |
Invalidates cached credentials, requiring password reauthentication. | sudo -k |
Ensures the next sudo command requires authentication. |
-b |
Runs the command in the background. | sudo -b sleep 60 |
Executes sleep 60 in the background with elevated privileges. |
-E |
Preserves the user's environment variables when running the command. | sudo -E env | grep HOME |
Displays the HOME environment variable of the original user. |
-- |
Stops processing options for sudo and treats subsequent arguments as part of the command. |
sudo -- ls --color=auto |
Ensures --color=auto is passed to ls. |
--help |
Displays help information for sudo and its options. |
sudo --help |
Shows a brief summary of sudo usage and available options. |
--version |
Displays the version information of sudo. |
sudo --version |
Outputs the current version of the sudo package. |
sudo -l
- Description: Displays the commands the user is allowed (or not allowed) to execute with
sudo. - Use Case: Verify your
sudoprivileges.
sudo -u john whoami
- Description: Runs
whoamias the userjohn. - Default: If
-uis not specified,sudoruns the command asroot.
sudo -g developers id
- Description: Runs
idwith the group set todevelopers.
sudo -i
- Description: Opens a login shell as
root, loading root's environment.
sudo -s
- Description: Opens a shell with the current user's environment but with elevated privileges.
sudo -k
- Description: Forces
sudoto forget the user's cached credentials, requiring reauthentication next time.
sudo -b sleep 60
- Description: Executes
sleep 60in the background with elevated privileges.
sudo -E env | grep HOME
- Description: Retains the user's environment when running the command.
sudo -- ls --color=auto
- Description: Ensures that options after
--are passed to the command, not interpreted bysudo.
sudo --help
- Description: Shows available options and usage information for
sudo.
sudo apt-get update
- Explanation: Updates package lists as the
rootuser.
sudo nano /etc/hosts
- Explanation: Opens
/etc/hostsfor editing with elevated privileges.
sudo systemctl restart nginx
- Explanation: Restarts the
nginxservice asroot.
sudo less /var/log/syslog
- Explanation: Views the system log file with read privileges.
sudo usermod -aG sudo username
- Explanation: Adds
usernameto thesudogroup, granting sudo privileges.
sudo -l
- Description: Lists the commands you are permitted to run with
sudo.
Sample Output:
Matching Defaults entries for alice on this host:
env_reset, mail_badpass,
secure_path=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
User alice may run the following commands on this host:
(ALL) ALL
sudo -u user1 id
- Description: Runs the
idcommand asuser1.
sudo -g hr id
- Description: Runs the
idcommand with the group set tohr.
sudo -u user1 -s /bin/bash
- Description: Starts a
bashshell asuser1.
-
Configuration Files:
/etc/sudoers: Main configuration file forsudo./etc/sudoers.d/: Directory for additionalsudoconfiguration files.
-
Log Files:
/var/log/auth.log(Debian/Ubuntu) or/var/log/secure(RHEL/CentOS): Logssudousage and authentication attempts.