Home › Linux root and sudo security › Step 5

Lesson 5: Role-based access control with groups

Step 5 of 13 in Linux root and sudo security · video 8:48

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

The lesson builds a small role-based model in which sudo rights belong to groups rather than to individual people. Three groups, webadmins, dbadmins and backupadmins, are created with groupadd, and one user per role is added with useradd -m -g <group> -s /bin/bash, then checked with id. Passwords are set with passwd and, without a prompt, by piping a user:password pair into chpasswd. Each role gets its own file under /etc/sudoers.d through visudo -f: web admins may control nginx and Apache with systemctl, edit nginx configuration, run nginx -t and certbot; database admins run their tools as the postgres and mysql service users; backup admins get rsync, zip, mount, find and similar tools plus a 60-minute timestamp_timeout. A deliberate typo shows visudo's recovery prompt, and the lesson ends with visudo -c reporting that the new files have the wrong permissions.

Good to know: wildcards in sudoers also match spaces and slashes, so /bin/systemctl * nginx matches systemctl stop sshd nginx too, and an editor allowed on /etc/nginx/* can reach other files. List exact commands, use sudoedit for file edits, and treat rsync, find or mount run as root as close to full root.

Check yourself

Answer in your head first, then open each question to see the answer.

1. What does the % in %webadmins ALL=(root) NOPASSWD: ... mean, and why is it useful?

% marks a group name, so the rule applies to every member of webadmins. Access is then managed by adding or removing group members rather than editing sudoers for each person.

2. You save a sudoers file in visudo with a missing = sign. What happens, and which option should you choose?

visudo reports the syntax error and asks 'What now?'. Choose e to edit again and fix it; x leaves without saving, while Q saves the broken file anyway, which can stop sudo working and should be avoided.

3. What does echo 'dbuser:DB123' | sudo chpasswd do?

chpasswd reads user:password pairs from standard input and sets each password, so no interactive passwd prompt is needed, which suits scripts and labs. The password ends up in shell history, so it is not a method for real secrets.

4. After adding three files to /etc/sudoers.d, sudo visudo -c reports bad permissions. What mode does it expect, and why does it matter?

0440: readable by root and the root group, writable by nobody. A sudoers file that others could change would let them grant themselves root, so sudo treats loose permissions as a security fault.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 4: Sudo privileges: limiting a user to specific commandsNext: Lesson 6: Sudoers and RBAC: fixing permissions and testing roles →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.