Home › Linux root and sudo security › Step 1

Lesson 1: Linux root access security

Step 1 of 13 in Linux root and sudo security · video 10:22

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

The first lesson starts where any root-access audit should: with the current state of the root account and a list of who already holds sudo rights on a RHEL-family system. It reads the root entry with sudo getent shadow root, then filters /etc/sudoers and the files in /etc/sudoers.d with grep for live rules that mention ALL, sudo or wheel, explaining why comment lines and error output are left out. sudo -l shows what the current user may run, and a newly created test user is refused with the "may not run sudo" message. A temporary root password is then set to compare su with su -: the first gives a root shell that stays in the old user's directory, the second a full login environment in /root. Along the way git is installed with dnf and the audit command is saved as an executable script in the course repository.

Good to know: the audit pipeline expands /etc/sudoers.d/* in your own shell before sudo runs. As a normal user you cannot read that folder, so its files can be skipped without a word (the error is hidden by 2>/dev/null). Run the whole pipeline in a root shell instead: sudo sh -c "grep -v '^#' /etc/sudoers /etc/sudoers.d/* | grep -E '(ALL|sudo|wheel)'".

Check yourself

Answer in your head first, then open each question to see the answer.

1. In the output of sudo getent shadow root, which field tells you whether root has a usable password?

The second field, which holds the password hash. A hash there means a password is set; a placeholder such as * instead of a hash means there is no password that can be used to log in.

2. Why does the audit pipeline start with grep -v '^#' before searching for ALL, sudo or wheel?

It drops every line that begins with #, that is comments and commented-out examples, which grant nothing. Only live lines reach the second grep, so it reports real privilege grants rather than documentation.

3. A new user runs sudo -l and gets "Sorry, user testuser may not run sudo on <host>". What does that tell you?

No rule in sudoers or sudoers.d matches that user, either by name or through a group such as wheel, so sudo will refuse every command they try. The account has no administrative rights until a rule or group membership is added.

4. After su you are root but pwd still shows your old home directory. What should you run instead, and why?

su -. The dash starts a login shell, so root's own environment is loaded and the shell starts in /root; plain su switches identity but keeps the current directory and much of the calling user's environment.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← About this pathNext: Lesson 2: Securing the root account and configuring sudo →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.