Home › Linux root and sudo security › Step 10
Lesson 10: Sudo session management and timestamp timeouts
Step 10 of 13 in Linux root and sudo security · video 5:09
What you will learn
- Check and refresh cached sudo credentials with sudo -v
- Set timestamp_timeout per user in a drop-in file
- Force a password for every sudo command with timeout 0
- Spot user-name typos that visudo cannot catch
About this lesson
sudo remembers a successful authentication for a while, and this lesson shows how to control that window per user. sudo -v validates and refreshes the cached credentials, and echo $? returning 0 confirms it worked. A new drop-in, /etc/sudoers.d/session-management, sets timestamp_timeout to 1 minute for quickuser, 30 minutes for longuser and 0 for securesession, and gives all three full sudo rights so that the timeout is the only difference between them. The test users are created and given passwords with chpasswd. The tests confirm the behaviour: quickuser is asked for the password again after sleep 65, and securesession has to authenticate for every single sudo command. Two small mistakes along the way, an extra space inside a password and a misspelt user name in the rule, show how easily a typo can make a policy silently fail to apply.
sudo -V lists the timeout defaults only when root runs it: sudo sudo -V | grep -i timeout.Check yourself
1. What does Defaults:quickuser timestamp_timeout=1 change?
sudo keeps quickuser's authentication cached for only 1 minute. Once that minute has passed, as after the lesson's sleep 65, the next sudo command asks for the password again.
2. What happens for a user whose timestamp_timeout is 0?
Credentials are never cached, so the user must type the password for every sudo command. It suits the most sensitive accounts, at the cost of convenience.
3. You run sudo -v and then echo $?, which prints 0. What does that mean?
sudo -v validated your credentials, asking for the password if needed, and refreshed the cached timestamp; exit status 0 means that succeeded, so you have a valid sudo session for the timeout period.
4. securesession is told it is not in the sudoers file, although visudo accepted the new file. What is the likely cause?
A mistyped user name in the rule (here 'secureusers' instead of 'securesession'). visudo checks syntax, not whether a named user exists, so the rule is valid but matches nobody; fix the name and test again.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99