Home › Linux root and sudo security › Step 4
Lesson 4: Sudo privileges: limiting a user to specific commands
Step 4 of 13 in Linux root and sudo security · video 5:00
What you will learn
- Create a drop-in rule file with visudo -f
- Mix NOPASSWD and password-protected commands for one user
- Check a single file with visudo -c -f
- Test allowed and forbidden commands from the user's shell
About this lesson
Instead of blanket ALL access, this lesson builds a rule file that lets a service account do only what its job needs. A user called serviceadmin is created with adduser, and sudo visudo -f /etc/sudoers.d/service-management opens a new drop-in file. It grants systemctl start, stop, restart and status plus journalctl as root without a password, while dnf update and dnf upgrade still require the user's own password. The file is checked on its own with visudo -c -f, then the policy is tested from the account's shell: systemctl status sshd and journalctl -u sshd -n 5 run straight away, and sudo cat /etc/shadow is refused with a "not allowed to execute" message that names the command and the host. The result is a three-level policy, with routine commands free, riskier ones behind a password and everything else forbidden, which is the principle of least privilege in practice.
systemctl status and journalctl run as root open a pager, and a pager can start a shell (!sh). Add --no-pager to the allowed commands, or use the NOEXEC tag, so the grant cannot turn into a root shell.Check yourself
1. How do you check only the new drop-in file for syntax errors, and what output means it is fine?
sudo visudo -c -f /etc/sudoers.d/service-management. It parses just that file and prints 'parsed OK' when the syntax is valid, so a mistake is caught before sudo reads the file.
2. In serviceadmin ALL=(root) NOPASSWD: /usr/bin/journalctl, what does the NOPASSWD: tag change?
It lets serviceadmin run the listed command as root without typing their own password. Commands on rules without NOPASSWD still ask for the password first.
3. Why are dnf update and dnf upgrade written without NOPASSWD while systemctl status is passwordless?
Checking a service is routine and low risk, but changing installed packages affects the whole system. Requiring the password for the package commands adds an authentication step where the impact is higher.
4. serviceadmin runs sudo cat /etc/shadow. What happens, and why?
After the password prompt sudo refuses with 'Sorry, user serviceadmin is not allowed to execute /bin/cat /etc/shadow as root'. No rule for this user lists cat, and sudo allows only commands that a rule matches.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99