Home › Linux root and sudo security › Step 4

Lesson 4: Sudo privileges: limiting a user to specific commands

Step 4 of 13 in Linux root and sudo security · video 5:00

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Instead of blanket ALL access, this lesson builds a rule file that lets a service account do only what its job needs. A user called serviceadmin is created with adduser, and sudo visudo -f /etc/sudoers.d/service-management opens a new drop-in file. It grants systemctl start, stop, restart and status plus journalctl as root without a password, while dnf update and dnf upgrade still require the user's own password. The file is checked on its own with visudo -c -f, then the policy is tested from the account's shell: systemctl status sshd and journalctl -u sshd -n 5 run straight away, and sudo cat /etc/shadow is refused with a "not allowed to execute" message that names the command and the host. The result is a three-level policy, with routine commands free, riskier ones behind a password and everything else forbidden, which is the principle of least privilege in practice.

Good to know: systemctl status and journalctl run as root open a pager, and a pager can start a shell (!sh). Add --no-pager to the allowed commands, or use the NOEXEC tag, so the grant cannot turn into a root shell.

Check yourself

Answer in your head first, then open each question to see the answer.

1. How do you check only the new drop-in file for syntax errors, and what output means it is fine?

sudo visudo -c -f /etc/sudoers.d/service-management. It parses just that file and prints 'parsed OK' when the syntax is valid, so a mistake is caught before sudo reads the file.

2. In serviceadmin ALL=(root) NOPASSWD: /usr/bin/journalctl, what does the NOPASSWD: tag change?

It lets serviceadmin run the listed command as root without typing their own password. Commands on rules without NOPASSWD still ask for the password first.

3. Why are dnf update and dnf upgrade written without NOPASSWD while systemctl status is passwordless?

Checking a service is routine and low risk, but changing installed packages affects the whole system. Requiring the password for the package commands adds an authentication step where the impact is higher.

4. serviceadmin runs sudo cat /etc/shadow. What happens, and why?

After the password prompt sudo refuses with 'Sorry, user serviceadmin is not allowed to execute /bin/cat /etc/shadow as root'. No rule for this user lists cat, and sudo allows only commands that a rule matches.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Zero-Trust Linux Administration: Complete Root Sudo Security

4.8★ · 5,090 students on Udemy

Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026

Get the course for $12.99
← Lesson 3: Sudoers mastery: reading the sudoers fileNext: Lesson 5: Role-based access control with groups →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.