4 ms·
> If you can sudo, you already have root, albeit limited. It's more of an ergonomic feature to discourage users logging in as root and destroying the system, th
by Jenk 3y ago
> If you can sudo, you already have root, albeit limited. It's more of an ergonomic feature to discourage users logging in as root and destroying the system, than any kind of reliable security compartmentalization.
I figured it was so you can identify the user who ran the command in an audit, instead of everyone just appear as "root"
- Guvante 3y agoMost use it like that the post uses a limited form where only certain commands can be ran.
- LinuxBender 3y agoI figured it was so you can identify the user who ran the command in an audit, instead of everyone just appear as "root" This goal can still be performed if auditd is enabled. The transition from non-root to root is tracked with the right rules in place. In my opinion it is best to rely on auditd and immutable after being tested rules as there are many ways to elevate privileges and many ways to improperly configure or bypass sudo. Auditd has a plugin to log directly to syslog and/or forwarded to ELK, Splunk or other tools. Auditd is also important when applications are exploited and someone then uses a privilege escalation vulnerability otherwise the person will just run it again after the machine/VM/container is re-imaged. Sudo was never intended to be a security control as much as it was to give a non sysadmin the ability to restart something or launch an on-demand process that required root or other accounts despite people using it in their documented controls. Many people will disagree with me on this as has been the case since the inception of sudo. One caveat being auditd with the most useful rules in place can get rather noisy and more to the point, costly in terms of storage and/or Splunk license. It comes down to the priorities of an organization or business.
- Jenk 3y agoYeah I meant more when folk `ssh root@host` over `su - root` But I do recall it being a lot more pleasant tracing who ran what sequence of commands, on a host used by many people in concurrent workflows, when it's sudo over su. It's also been some ~20 years since I've been in a role that required I do this so I (most probably) have forgotten a lot.
- orev 3y agoOne of the main benefits of sudo is that nobody needs to know the root password to switch to root (like one would need when using su). The actual root password can be saved in some break glass system, and admins only need to manage their own passwords.
- Jenk 3y agoThat is a penny drop moment for me. You are absolutely right that that is the primary purpose.