What is sudo?

sudo is a Unix and Linux program that runs a single command as another user, usually root. The name is short for superuser do.

It exists so that an administrator does not have to log in as root to do administrative work. They log in as themselves, and elevate for the one command that needs it.

sudo systemctl restart nginx

That command runs systemctl restart nginx with root authority, logs that the person ran it, and returns the shell to ordinary rights.

Named user → Permitted command → Audit log
Named user → Permitted command → Audit log

Why it was a good idea

Before sudo, administrative work meant logging in as root directly. Three problems followed.

Problem with logging in as root What sudo changed
Everything in the session runs with full authority, including mistakes Only the named command is elevated
The log shows root, not which person it was The log shows the person who elevated
The root password has to be shared with everyone who needs it Nobody needs the root password

That third point is the one people forget. sudo's original purpose was to make the root password unnecessary, and in doing so it removed a shared credential from circulation.

How it is configured

Rules live in /etc/sudoers and in files under /etc/sudoers.d/, edited with visudo so a syntax error cannot lock everyone out. A rule names who may run what, on which hosts, and as which user.

alice ALL=(root) /usr/bin/systemctl restart nginx

That line lets alice restart one service as root, and nothing else.

Where it falls short at scale

sudo is sound. The difficulty is operating it across a large environment.

The rules live on each machine. A policy change means distributing a file to every host and confirming it arrived. Configuration management helps and adds its own trust questions.

ALL=(ALL) ALL is everywhere. The most common real-world rule grants unrestricted root. It is quick to write, hard to review, and functionally identical to handing out the root password.

Rules are hard to audit. Answering "who can become root on which of our 900 hosts" means reading 900 configurations.

Elevation is standing, not requested. If a rule says you may elevate, you may elevate at any time, with no approval and no window. That is the opposite of just-in-time access.

A command rule can often be escaped. Many permitted binaries can spawn a shell or read arbitrary files, so a narrow-looking rule can yield full root in one step.

Coverage stops at Unix. Windows and macOS need their own answer, and a split policy is a policy nobody has read end to end.

What the kit does

Item

  • Endpoint elevation, delegation, least privilege, application and command control, just-in-time elevation, and privileged activity auditing. Windows is the most complete today. Apple Mac and Unix/Linux are expanding.
  • Brokered SSH sessions in the browser with approvals, and command restriction that blocks dangerous commands as they are typed
  • Recorded SSH sessions with replay, on the Level 3 kit
  • Discover accounts, privileged group membership, and SSH keys across Linux and Unix hosts
  • Rotate and propagate credentials on Linux and Unix, including on air-gapped systems

Windows is the most complete elevation surface today, and Unix and Linux coverage is expanding, which is what the availability word on the first row records. See privileged user management.

Common questions

Is sudo insecure?

No. sudo is a well-maintained program doing what it was designed to do. The risk comes from how it is configured and from the absence of approval, expiry, and central review around it.

What is the difference between sudo and su?

su switches to another user for a whole session and needs that user's password. sudo runs one command and uses your own password, so the root password does not have to exist in anyone's memory.

Does sudo -i defeat the purpose?

Largely, yes. It opens a full interactive root shell, so you are back to a session where everything runs with full authority. It is logged, which is better than nothing, but the scoping benefit is gone.

Should we replace sudo?

Usually not replace. Govern. Keep sudo where it works, remove the unrestricted rules, and put approval, a time limit, and a central record around elevation that matters.

How do I see who can use sudo on a host?

sudo -l lists the rules that apply to the current user. Answering the same question across every host is the part that needs tooling.

Related pages

Sources