Home › Linux root and sudo security › Step 7
Lesson 7: Advanced sudoers configuration: logging, aliases and denials
Step 7 of 13 in Linux root and sudo security · video 10:32
What you will learn
- Record sudo sessions with log_input and log_output
- Tune timestamp_timeout, passwd_tries and badpass_message per user
- Group commands into named sets with Cmnd_Alias
- Deny specific commands with ! and know its limits
About this lesson
A high-risk account, secureuser, gets a closely watched sudo policy in /etc/sudoers.d/advanced-security. Per-user Defaults switch on log_input and log_output to record the keystrokes and screen output of its sudo sessions, send the account's sudo events to a dedicated log file in /var/log, set timestamp_timeout to 5 minutes, allow only two password attempts with passwd_tries=2 and replace the wrong-password text with a custom badpass_message. Cmnd_Alias groups commands into named sets: monitoring tools such as htop and ps run without a password, while log analysis with tail, head, grep and awk, and editing with nano, need one. A final rule uses ! to deny passwd, su, sh and bash. After visudo -c -f passes, tests show ps running without a password, sudo passwd root refused, and the dedicated log file recording each attempt, including the denied ones.
sudoreplay. The default for passwd_tries is 3. A ! denial is easy to sidestep with a copied or renamed program, so rely on granting narrow commands rather than on denials.Check yourself
1. What do Defaults:secureuser log_input, log_output record?
log_input records what the user types during sudo commands and log_output records what those commands print. Together they allow a full review of a session, at the cost of large logs, so they suit high-risk accounts.
2. Which setting makes sudo give up after two wrong passwords for secureuser, and why use it?
Defaults:secureuser passwd_tries=2. After two failed attempts the sudo command stops, which slows down anyone guessing the password at the terminal.
3. Write a Cmnd_Alias for htop and ps and a rule that lets secureuser run it as root without a password.
Cmnd_Alias MONITORING = /usr/bin/htop, /usr/bin/ps and secureuser ALL=(root) NOPASSWD: MONITORING. The alias name, in capitals, stands for the whole list, so the rule stays short and the list is kept in one place.
4. secureuser has a rule secureuser ALL=(root) !/usr/bin/passwd, !/usr/bin/su, !/bin/sh, !/bin/bash. What happens on sudo passwd root?
sudo refuses with 'Sorry, user secureuser is not allowed to execute ...' because the ! entries explicitly deny those commands. Treat such denials as a safety net: they match exact paths, so the main protection is still granting only narrow commands.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.
Zero-Trust Linux Administration: Complete Root Sudo Security
Coupon LINUX2ZEROTRUST: $12.99 until 10/28/2026
Get the course for $12.99