Home / Alt manpages / sudo(8)

  • sudo(8)
  • Admin command
  • linux

Use sudo Safely: Permissions, Credential Caching and sudoedit

You will finish with a repeatable sudo workflow: identify what your account may run, execute one deliberate command, control the credential cache, and edit a protected file without handing an editor an unrestricted root shell. These examples match sudo 1.9.15p5 from the Ubuntu sudo package installed on this machine.

Allow about 15 minutes. You need a shell, an account that is permitted by the local sudo policy, and a command or file that you are authorised to administer. Most checks are ordinary commands. The commands that invoke sudo may authenticate and may change system state, so read each command before running it.

1. Check the installed version and your permission

Start with information that does not change the machine:

$ sudo --version
Sudo version 1.9.15p5
Sudoers policy plugin version 1.9.15p5
Sudoers file grammar version 50
$ sudo -l

The first command prints the front-end and configured plugin versions. The second asks the active security policy to list your privileges. It may ask for your password. A successful listing tells you which commands the policy permits; it does not grant permission to substitute a different command or argument.

Checkpoint: if sudo -l says that your user is not in the sudoers file, stop here. Do not try sudo -s, sudo -i or a different username. Policy administration belongs to the system administrator and is normally performed through visudo, which checks sudoers syntax before installing a change.

2. Run one exact command

Use an absolute path when the command matters, and keep the arguments visible:

$ command -v systemctl
/usr/bin/systemctl
$ sudo /usr/bin/systemctl status example.service

Replace example.service with the service you have been asked to inspect. A status query normally reads state, but the policy still decides whether it is allowed. For a harmless identity check, use:

$ sudo id -u
0

The default target user is usually root. Use -u when the policy explicitly allows another account:

$ sudo -u deploy -- /usr/bin/id -un
deploy

The -- separates sudo options from the command. Do not put an untrusted variable into a command line and assume sudo will make it safe. A permitted interpreter, shell or text editor can often perform more actions than the command name suggests.

3. Make authentication behaviour explicit

With the default sudoers policy, successfully authenticating normally creates a per-terminal credential record for 15 minutes unless policy changes timestamp_timeout. The timestamp format uses records restricted by a terminal by default, so authenticating in one terminal does not necessarily authenticate another.

To test whether existing credentials are valid without running a command, use validation mode:

$ sudo -v

There may be no output on success. To check non-interactively, without prompting and without updating the cache, use:

$ sudo -Nnv
$ printf '%s\n' "$?"
0

Here -n refuses any prompt, -N prevents a successful check from updating the cached credentials, and -v performs validation without a command. A non-zero status means that the check did not establish valid authorisation; record the error rather than treating it as permission to continue.

When you are finished with a sensitive session, invalidate the current session's cached credentials:

$ sudo -k
$ sudo -Nnv
sudo: a password is required
$ printf '%s\n' "$?"
1

-k does not require a password and affects the current terminal record. -K removes every cached credential for your user and cannot be combined with a command. These options revoke cached authentication; they do not undo a command already run.

4. Edit one protected file with sudoedit

Use sudoedit, or sudo -e, when the task is to edit a file rather than run an editor as root:

$ sudoedit /etc/example.conf

Sudo creates a temporary copy owned by you, starts the policy-selected editor, and copies the changed file back only after the edit. The sudoers policy checks SUDO_EDITOR, then VISUAL, then EDITOR, before its configured editor list. Set the editor only to a program you trust:

$ command -v vi
/usr/bin/vi
$ SUDO_EDITOR=/usr/bin/vi sudoedit /etc/example.conf

Warning: this command can replace a system configuration file. Keep the old contents available, make one focused change, and validate the service configuration before restarting anything. If the editor exits with an empty temporary file, sudoedit asks before installing it. If installation fails, sudo leaves the edited copy in a temporary file and reports the problem.

Do not use sudo sh -c '...' as a shortcut for editing. It turns quoting mistakes and editor configuration into a root command. Do not expect sudoedit to follow an arbitrary symbolic link: current sudo versions reject symbolic links and apply additional restrictions to writable paths unless policy explicitly permits them.

5. Understand sudo.conf before changing it

/etc/sudo.conf configures the sudo front-end, not the ordinary command permissions. It can select policy, audit and I/O plugins, set paths such as an askpass helper, and enable debug logging. If it has no Plugin lines, sudoers is used by default.

That distinction prevents a common troubleshooting error: adding a line to sudo.conf will not grant your account a new command. Permission rules belong to sudoers or another configured policy plugin. Plugin shared objects are security-sensitive; the manual requires them to be owned by UID 0 and writable only by their owner.

If a graphical program has no terminal and needs password input, sudo can use -A with an askpass helper from SUDO_ASKPASS or the Path askpass setting in /etc/sudo.conf. This is a credential boundary, not a way around policy:

$ SUDO_ASKPASS=/usr/bin/ssh-askpass sudo -A -v

Only use a helper whose path and ownership you have checked. Never put a password in a command argument or an environment variable merely to avoid the prompt.

6. Diagnose failures without widening access

First capture the exact command and status. Common messages have different causes:

  • sudo: a password is required with -n means no usable cached authentication was available.
  • user is not in the sudoers file means the policy rejected the account; ask an administrator to review the rule.
  • command not found may mean the command is absent or its path is not allowed by policy. Check it with command -v as the invoking user.
  • A command can be allowed while its arguments are rejected. Read the rule shown by sudo -ll on sudo 1.9.15 and later, where supported.

Do not fix a denial by adding -E, switching to -i, or preserving a broad environment. The policy may reject environment preservation, and a different environment can change which executable or configuration a privileged command uses. Ask for the narrowest policy change that matches the task.

Done means

  • sudo --version identifies the installed sudo release and plugins.
  • sudo -l was checked before an administrative command was attempted.
  • The command and target user were explicit, with no unnecessary shell.
  • Credential validation and revocation used -v, -Nnv, -k or -K deliberately.
  • Protected files were edited with sudoedit, and the resulting configuration was checked before any service restart.
  • /etc/sudo.conf was treated as front-end and plugin configuration, not as the place to grant permissions.