Home › Linux root and sudo security › Step 10

Lesson 10: Sudo session management and timestamp timeouts

Step 10 of 13 in Linux root and sudo security · video 5:09

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

sudo remembers a successful authentication for a while, and this lesson shows how to control that window per user. sudo -v validates and refreshes the cached credentials, and echo $? returning 0 confirms it worked. A new drop-in, /etc/sudoers.d/session-management, sets timestamp_timeout to 1 minute for quickuser, 30 minutes for longuser and 0 for securesession, and gives all three full sudo rights so that the timeout is the only difference between them. The test users are created and given passwords with chpasswd. The tests confirm the behaviour: quickuser is asked for the password again after sleep 65, and securesession has to authenticate for every single sudo command. Two small mistakes along the way, an extra space inside a password and a misspelt user name in the rule, show how easily a typo can make a policy silently fail to apply.

Good to know: sudo -V lists the timeout defaults only when root runs it: sudo sudo -V | grep -i timeout.

Check yourself

Answer in your head first, then open each question to see the answer.

1. What does Defaults:quickuser timestamp_timeout=1 change?

sudo keeps quickuser's authentication cached for only 1 minute. Once that minute has passed, as after the lesson's sleep 65, the next sudo command asks for the password again.

2. What happens for a user whose timestamp_timeout is 0?

Credentials are never cached, so the user must type the password for every sudo command. It suits the most sensitive accounts, at the cost of convenience.

3. You run sudo -v and then echo $?, which prints 0. What does that mean?

sudo -v validated your credentials, asking for the password if needed, and refreshed the cached timestamp; exit status 0 means that succeeded, so you have a valid sudo session for the timeout period.

4. securesession is told it is not in the sudoers file, although visudo accepted the new file. What is the likely cause?

A mistyped user name in the rule (here 'secureusers' instead of 'securesession'). visudo checks syntax, not whether a named user exists, so the rule is valid but matches nobody; fix the name and test again.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 9: Testing sudo security with environment variablesNext: Lesson 11: Debugging and troubleshooting sudo policies →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.