Home › Linux root and sudo security › Step 3
Lesson 3: Sudoers mastery: reading the sudoers file
Step 3 of 13 in Linux root and sudo security · video 6:39
What you will learn
- Validate all sudoers files with visudo -c
- Read a rule as user, host, run-as user and command
- Understand the env_reset, env_keep and secure_path defaults
- Recognise why NOPASSWD: ALL is convenient but risky
About this lesson
A tour of the default /etc/sudoers on a RHEL-family system before any changes are made. The lesson shortens the prompt with export PS1, checks every sudoers file for syntax errors with sudo visudo -c, then strips comments and blank lines with grep -v '^#' | grep -v '^$' so that only live settings remain. Each line is then explained: Defaults such as env_reset, the env_keep lists of variables that survive into sudo, and secure_path, which fixes the directories sudo searches for commands. The rule syntax is broken down as user, host, run-as user and commands, using the root line, the %wheel group line (the percent sign marks a group) and a NOPASSWD rule for the presenter's own account, whose risk if that account is compromised is spelt out. Finally /etc/sudoers.d is listed: it needs sudo to read and is still empty, ready for modular rule files.
Check yourself
1. What does sudo visudo -c do, and when would you run it?
It parses /etc/sudoers and the files it includes and reports syntax errors without opening an editor. Running it before and after a change confirms that sudo will still accept its configuration.
2. Break down the rule %wheel ALL=(ALL) ALL field by field.
%wheel means members of the wheel group (the % marks a group), the first ALL is any host, (ALL) is run as any user, and the final ALL is any command. It gives wheel members full sudo rights, the RHEL default.
3. What is the security purpose of the secure_path Defaults setting?
It replaces the PATH used for commands run through sudo with a fixed list of trusted system directories. A malicious program placed earlier in a user's own PATH is therefore never picked up and run as root.
4. Why is a line like admin ALL=(ALL) NOPASSWD: ALL risky, even though it is common on cloud images?
It grants unlimited root access with no password check, so anyone who takes over that account, or finds its session unattended, becomes root at once. The sudo password prompt no longer acts as a second barrier.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99