Home › Linux root and sudo security › Step 11

Lesson 11: Debugging and troubleshooting sudo policies

Step 11 of 13 in Linux root and sudo security · video 3:24

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

When a user reports that sudo will not do what they expect, the first step is to see the policy exactly as sudo sees it. This short lesson uses sudo -U quickuser -l, run by an administrator, to list another user's effective sudo rights: the Defaults that apply to them, such as env_reset, secure_path and the one-minute timestamp_timeout set earlier, and the commands they may run. Because the output is resolved, rights that come from a group rule such as %dbadmins appear too, which makes it the command to reach for when onboarding, auditing or troubleshooting. The lesson then runs commands as the user with sudo -u dbuser, for example sudo -u dbuser sudo -l 2>&1 | head -10, where 2>&1 folds error messages into the piped output, and sudo -u dbuser sudo systemctl restart nginx, which reproduces the user's refusal message for a command their role does not cover.

Check yourself

Answer in your head first, then open each question to see the answer.

1. What is the difference between sudo -U quickuser -l and sudo -u quickuser <command>?

-U with -l lists another user's sudo privileges and needs administrator rights; -u runs a command as that user. Use -U -l to read the policy and -u to reproduce what the user actually sees.

2. dbuser gets their sudo rights only through a group. Will sudo -U dbuser -l show them?

Yes. The listing shows the effective policy, so rules granted through a group such as %dbadmins appear as well as rules that name the user directly.

3. What does 2>&1 add in sudo -u dbuser sudo -l 2>&1 | head -10?

It sends standard error to the same place as standard output, so error messages also go through the pipe to head. Without it, errors would bypass the pipe and could be missed or appear out of order.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 10: Sudo session management and timestamp timeoutsNext: Lesson 12: Cleaning up sudoers and removing test users →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.