Home › Linux root and sudo security › Step 7

Lesson 7: Advanced sudoers configuration: logging, aliases and denials

Step 7 of 13 in Linux root and sudo security · video 10:32

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

A high-risk account, secureuser, gets a closely watched sudo policy in /etc/sudoers.d/advanced-security. Per-user Defaults switch on log_input and log_output to record the keystrokes and screen output of its sudo sessions, send the account's sudo events to a dedicated log file in /var/log, set timestamp_timeout to 5 minutes, allow only two password attempts with passwd_tries=2 and replace the wrong-password text with a custom badpass_message. Cmnd_Alias groups commands into named sets: monitoring tools such as htop and ps run without a password, while log analysis with tail, head, grep and awk, and editing with nano, need one. A final rule uses ! to deny passwd, su, sh and bash. After visudo -c -f passes, tests show ps running without a password, sudo passwd root refused, and the dedicated log file recording each attempt, including the denied ones.

Good to know: recorded sessions are kept as I/O logs under /var/log/sudo-io and played back with sudoreplay. The default for passwd_tries is 3. A ! denial is easy to sidestep with a copied or renamed program, so rely on granting narrow commands rather than on denials.

Check yourself

Answer in your head first, then open each question to see the answer.

1. What do Defaults:secureuser log_input, log_output record?

log_input records what the user types during sudo commands and log_output records what those commands print. Together they allow a full review of a session, at the cost of large logs, so they suit high-risk accounts.

2. Which setting makes sudo give up after two wrong passwords for secureuser, and why use it?

Defaults:secureuser passwd_tries=2. After two failed attempts the sudo command stops, which slows down anyone guessing the password at the terminal.

3. Write a Cmnd_Alias for htop and ps and a rule that lets secureuser run it as root without a password.

Cmnd_Alias MONITORING = /usr/bin/htop, /usr/bin/ps and secureuser ALL=(root) NOPASSWD: MONITORING. The alias name, in capitals, stands for the whole list, so the rule stays short and the list is kept in one place.

4. secureuser has a rule secureuser ALL=(root) !/usr/bin/passwd, !/usr/bin/su, !/bin/sh, !/bin/bash. What happens on sudo passwd root?

sudo refuses with 'Sorry, user secureuser is not allowed to execute ...' because the ! entries explicitly deny those commands. Treat such denials as a safety net: they match exact paths, so the main protection is still granting only narrow commands.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 6: Sudoers and RBAC: fixing permissions and testing rolesNext: Lesson 8: Sudoers environment security →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.