Home › Linux root and sudo security › Step 2

Lesson 2: Securing the root account and configuring sudo

Step 2 of 13 in Linux root and sudo security · video 7:22

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

This lesson hardens the root account and moves day-to-day administration onto sudo. The root password is locked with sudo passwd -l root, after which getent shadow root shows an exclamation mark at the start of the password field, and su - fails with an authentication error even when the correct password is typed. Everyday sudo use follows: checking a service with systemctl, installing a package with dnf, editing /etc/hosts, and reading sudo events from /var/log/secure. The sudoers file is opened safely with visudo, and the test user from lesson 1 gains full rights by joining the wheel group with usermod -aG wheel, confirmed with groups and sudo whoami. Finally, direct root logins over SSH are switched off by setting PermitRootLogin no in /etc/ssh/sshd_config, checking the file with sshd -t, restarting sshd and proving that an SSH login as root is now refused.

Good to know: passwd -l does not stop SSH key logins, which is why PermitRootLogin no matters. On RHEL 9 a file in /etc/ssh/sshd_config.d can override the line you edit; sudo sshd -T | grep -i permitrootlogin shows the value sshd really uses.

Check yourself

Answer in your head first, then open each question to see the answer.

1. After sudo passwd -l root, what does sudo getent shadow root show, and what happens when someone tries su - with the correct root password?

The password field now starts with !, which marks the hash as locked. su - fails with an authentication error, because a locked password is rejected even when it is typed correctly.

2. Which command gives an existing user full sudo rights on RHEL without editing sudoers, and why does it work?

sudo usermod -aG wheel testuser. RHEL's default sudoers already grants the %wheel group full access, so joining wheel is enough; -a appends the group so the user keeps their other supplementary groups.

3. Where would you look for recent sudo use on a RHEL system, and with what command?

In /var/log/secure, which records authentication events including sudo. sudo grep sudo /var/log/secure | tail -5 shows the last five matching lines; sudo is needed because the log is readable only by root.

4. You have set PermitRootLogin no in /etc/ssh/sshd_config. What should you run before and after restarting sshd?

Run sudo sshd -t first: no output means the configuration is valid, so the restart will not fail on a broken file. Then sudo systemctl restart sshd and test with ssh root@localhost, which should now end in 'Permission denied'.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 1: Linux root access securityNext: Lesson 3: Sudoers mastery: reading the sudoers file →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.