Home › Linux root and sudo security › Step 6
Lesson 6: Sudoers and RBAC: fixing permissions and testing roles
Step 6 of 13 in Linux root and sudo security · video 6:39
What you will learn
- Set sudoers.d files to root:root ownership and mode 0440
- Review a user's rights with sudo -l
- Test each role's allowed and refused commands
- Adjust a rule when the service name changes
About this lesson
The role files from lesson 5 are finished and tested here. Because visudo -c complained about bad permissions, the files are given root:root ownership with chown and mode 0440 with chmod; the lesson shows that fixing ownership alone is not enough and the check passes only once both are right. Each role is then tried from its own account, entered with sudo su - <user>, and sudo -l lists the defaults and the commands that user may run. The web user can query nginx with systemctl but cannot install it with dnf, which turns into a ticket for a system administrator. The database role meets a practical snag: MySQL will not install on the lesson's system, so MariaDB is installed with dnf install mariadb-server -y and the rule is edited to match the mariadb service. The backup user can run rsync but is refused when reading /etc/passwd through sudo, confirming that each role stays inside its limits.
Check yourself
1. visudo -c still reports bad permissions after sudo chown root:root on each file. What is missing?
The mode. Ownership and permissions are separate settings, so each file also needs sudo chmod 0440 /etc/sudoers.d/<file>; after that visudo -c parses the files without errors.
2. What does sudo -l show the user who runs it?
The Defaults that apply to them and the commands they may run through sudo, including which of them need no password. It is the quickest way for a user to check their own rights.
3. The web admin tries sudo dnf install nginx and is refused. Is that correct, and what should happen next?
Yes. The webadmins rule covers service control and nginx configuration, not package installation, so the user raises a ticket and a system administrator installs the package; the web admin can then manage it.
4. The dbadmins rule names the mysql service, but the server now runs MariaDB. What has to change, and why?
Edit the dbadmins file with visudo so the systemctl rule names mariadb instead of mysql. sudo matches the command and its arguments, so a rule for mysql does not allow systemctl status mariadb.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99