Home › Linux root and sudo security › Step 1
Lesson 1: Linux root access security
Step 1 of 13 in Linux root and sudo security · video 10:22
What you will learn
- Read the root password state with getent shadow
- Find every live sudo rule in sudoers and sudoers.d with grep
- Check your own and another user's rights with sudo -l
- Tell su and su - apart by directory and environment
About this lesson
The first lesson starts where any root-access audit should: with the current state of the root account and a list of who already holds sudo rights on a RHEL-family system. It reads the root entry with sudo getent shadow root, then filters /etc/sudoers and the files in /etc/sudoers.d with grep for live rules that mention ALL, sudo or wheel, explaining why comment lines and error output are left out. sudo -l shows what the current user may run, and a newly created test user is refused with the "may not run sudo" message. A temporary root password is then set to compare su with su -: the first gives a root shell that stays in the old user's directory, the second a full login environment in /root. Along the way git is installed with dnf and the audit command is saved as an executable script in the course repository.
/etc/sudoers.d/* in your own shell before sudo runs. As a normal user you cannot read that folder, so its files can be skipped without a word (the error is hidden by 2>/dev/null). Run the whole pipeline in a root shell instead: sudo sh -c "grep -v '^#' /etc/sudoers /etc/sudoers.d/* | grep -E '(ALL|sudo|wheel)'".Check yourself
1. In the output of sudo getent shadow root, which field tells you whether root has a usable password?
The second field, which holds the password hash. A hash there means a password is set; a placeholder such as * instead of a hash means there is no password that can be used to log in.
2. Why does the audit pipeline start with grep -v '^#' before searching for ALL, sudo or wheel?
It drops every line that begins with #, that is comments and commented-out examples, which grant nothing. Only live lines reach the second grep, so it reports real privilege grants rather than documentation.
3. A new user runs sudo -l and gets "Sorry, user testuser may not run sudo on <host>". What does that tell you?
No rule in sudoers or sudoers.d matches that user, either by name or through a group such as wheel, so sudo will refuse every command they try. The account has no administrative rights until a rule or group membership is added.
4. After su you are root but pwd still shows your old home directory. What should you run instead, and why?
su -. The dash starts a login shell, so root's own environment is loaded and the shell starts in /root; plain su switches identity but keeps the current directory and much of the calling user's environment.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99