Home › Linux root and sudo security › Step 5
Lesson 5: Role-based access control with groups
Step 5 of 13 in Linux root and sudo security · video 8:48
What you will learn
- Create role groups and users with groupadd and useradd
- Set passwords without a prompt using chpasswd
- Grant a whole group rights with a %group rule
- Recover safely when visudo finds a syntax error
About this lesson
The lesson builds a small role-based model in which sudo rights belong to groups rather than to individual people. Three groups, webadmins, dbadmins and backupadmins, are created with groupadd, and one user per role is added with useradd -m -g <group> -s /bin/bash, then checked with id. Passwords are set with passwd and, without a prompt, by piping a user:password pair into chpasswd. Each role gets its own file under /etc/sudoers.d through visudo -f: web admins may control nginx and Apache with systemctl, edit nginx configuration, run nginx -t and certbot; database admins run their tools as the postgres and mysql service users; backup admins get rsync, zip, mount, find and similar tools plus a 60-minute timestamp_timeout. A deliberate typo shows visudo's recovery prompt, and the lesson ends with visudo -c reporting that the new files have the wrong permissions.
/bin/systemctl * nginx matches systemctl stop sshd nginx too, and an editor allowed on /etc/nginx/* can reach other files. List exact commands, use sudoedit for file edits, and treat rsync, find or mount run as root as close to full root.Check yourself
1. What does the % in %webadmins ALL=(root) NOPASSWD: ... mean, and why is it useful?
% marks a group name, so the rule applies to every member of webadmins. Access is then managed by adding or removing group members rather than editing sudoers for each person.
2. You save a sudoers file in visudo with a missing = sign. What happens, and which option should you choose?
visudo reports the syntax error and asks 'What now?'. Choose e to edit again and fix it; x leaves without saving, while Q saves the broken file anyway, which can stop sudo working and should be avoided.
3. What does echo 'dbuser:DB123' | sudo chpasswd do?
chpasswd reads user:password pairs from standard input and sets each password, so no interactive passwd prompt is needed, which suits scripts and labs. The password ends up in shell history, so it is not a method for real secrets.
4. After adding three files to /etc/sudoers.d, sudo visudo -c reports bad permissions. What mode does it expect, and why does it matter?
0440: readable by root and the root group, writable by nobody. A sudoers file that others could change would let them grant themselves root, so sudo treats loose permissions as a security fault.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99