- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Meaning of % in %sysadmin ALL=NOPASSWD:/bin/su - r...
Operating System - HP-UX
1820485
Members
2381
Online
109624
Solutions
Forums
Categories
Company
Local Language
юдл
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
юдл
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-25-2011 12:32 AM
тАО04-25-2011 12:32 AM
Meaning of % in %sysadmin ALL=NOPASSWD:/bin/su - root???-sudoers file
i have seen the below line on the /etc/sudoers file
%sysadmin ALL=NOPASSWD:/bin/su - root
So it says that the person belongs to the sysadmin can able swith over to root without password, but what is the symbol(%) like percentage.. what was the meaning of that. Thanks!
%sysadmin ALL=NOPASSWD:/bin/su - root
So it says that the person belongs to the sysadmin can able swith over to root without password, but what is the symbol(%) like percentage.. what was the meaning of that. Thanks!
2 REPLIES 2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-25-2011 04:40 AM
тАО04-25-2011 04:40 AM
Re: Meaning of % in %sysadmin ALL=NOPASSWD:/bin/su - root???-sudoers file
The "%" sign tells sudo you're giving sudo access to all users in _group_ "sysadmin", not to _user_ "sysadmin" only.
MK
MK
MK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-25-2011 08:17 AM
тАО04-25-2011 08:17 AM
Re: Meaning of % in %sysadmin ALL=NOPASSWD:/bin/su - root???-sudoers file
Everything in sudo is group related: If you see %sysadmin then there will be an entry in the /etc/group file for sysadmin.
If you see:
"...DISCOVER ALL=NOPASSWD:/bin/su - root..."
: then DISCOVER will be a made up SUDO group that has no entry in /etc/group, but, will have a pointer to a real /etc/group group. Like this:
User_Alias DISCOVER = %oracle
##########################
%sysadmin ALL=NOPASSWD:/bin/su - root
This means for any user belonging to the /etc/group 'sysadmin' a password is not required when running a sudo command. "...:/bin/su - root..." is a notorius security flaw in SUDO since configuration says "..Ok for any user in the /etc/group 'sysadmin' to log directly into root without using a password.
The reason that it is a flaw is because it bypasses THE ROOT PASSWORD. (* So why have a root password if you're going to do this? *)
If you see:
"...DISCOVER ALL=NOPASSWD:/bin/su - root..."
: then DISCOVER will be a made up SUDO group that has no entry in /etc/group, but, will have a pointer to a real /etc/group group. Like this:
User_Alias DISCOVER = %oracle
##########################
%sysadmin ALL=NOPASSWD:/bin/su - root
This means for any user belonging to the /etc/group 'sysadmin' a password is not required when running a sudo command. "...:/bin/su - root..." is a notorius security flaw in SUDO since configuration says "..Ok for any user in the /etc/group 'sysadmin' to log directly into root without using a password.
The reason that it is a flaw is because it bypasses THE ROOT PASSWORD. (* So why have a root password if you're going to do this? *)
Support Fatherhood - Stop Family Law
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
Company
Learn About
News and Events
Support
© Copyright 2025 Hewlett Packard Enterprise Development LP