Home › Linux root and sudo security › Step 2
Lesson 2: Securing the root account and configuring sudo
Step 2 of 13 in Linux root and sudo security · video 7:22
What you will learn
- Lock the root password and recognise the lock in /etc/shadow
- Grant full sudo rights on RHEL through the wheel group
- Find sudo activity in /var/log/secure
- Block root SSH logins and validate sshd_config with sshd -t
About this lesson
This lesson hardens the root account and moves day-to-day administration onto sudo. The root password is locked with sudo passwd -l root, after which getent shadow root shows an exclamation mark at the start of the password field, and su - fails with an authentication error even when the correct password is typed. Everyday sudo use follows: checking a service with systemctl, installing a package with dnf, editing /etc/hosts, and reading sudo events from /var/log/secure. The sudoers file is opened safely with visudo, and the test user from lesson 1 gains full rights by joining the wheel group with usermod -aG wheel, confirmed with groups and sudo whoami. Finally, direct root logins over SSH are switched off by setting PermitRootLogin no in /etc/ssh/sshd_config, checking the file with sshd -t, restarting sshd and proving that an SSH login as root is now refused.
passwd -l does not stop SSH key logins, which is why PermitRootLogin no matters. On RHEL 9 a file in /etc/ssh/sshd_config.d can override the line you edit; sudo sshd -T | grep -i permitrootlogin shows the value sshd really uses.Check yourself
1. After sudo passwd -l root, what does sudo getent shadow root show, and what happens when someone tries su - with the correct root password?
The password field now starts with !, which marks the hash as locked. su - fails with an authentication error, because a locked password is rejected even when it is typed correctly.
2. Which command gives an existing user full sudo rights on RHEL without editing sudoers, and why does it work?
sudo usermod -aG wheel testuser. RHEL's default sudoers already grants the %wheel group full access, so joining wheel is enough; -a appends the group so the user keeps their other supplementary groups.
3. Where would you look for recent sudo use on a RHEL system, and with what command?
In /var/log/secure, which records authentication events including sudo. sudo grep sudo /var/log/secure | tail -5 shows the last five matching lines; sudo is needed because the log is readable only by root.
4. You have set PermitRootLogin no in /etc/ssh/sshd_config. What should you run before and after restarting sshd?
Run sudo sshd -t first: no output means the configuration is valid, so the restart will not fail on a broken file. Then sudo systemctl restart sshd and test with ssh root@localhost, which should now end in 'Permission denied'.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99