Bug #14381
openDirective Sudoers allow both passwordless sudo and all commands.
Description
Hello Rudder,
During my testing yesterday we attempted to allow a user on our staging server to execute passwordless sudo and all commands, but we found that when you enable the following options in the directive:
- Allow the entity to execute the given commands without entering his password (true)
- Allow the entity to execute all commands (true)
- Commands allowed to this entity - Optional (EMPTY)
The sudeors file results in the following:
#includedir /etc/sudoers.d # begin_section_user user ALL=(ALL) ALL
This does allow the user to execute sudo commands but prompts for a password our goal would be to allow all sudo commands on staging without entering a password.
Thank you!
Updated by Alexis Mousset over 5 years ago
- Description updated (diff)
- Category set to Techniques
- Target version set to 5.0.7
Updated by François ARMAND over 5 years ago
- Target version changed from 5.0.7 to 5.0.9
Updated by Vincent MEMBRÉ over 5 years ago
- Target version changed from 5.0.9 to 5.0.10
Updated by Nicolas CHARLES over 5 years ago
Hi Matthew
What would be the expected content of sudo config file to achieve that correctly in your opinion?
Updated by Matthew Frost over 5 years ago
Hello Nicolas,
It would be:
myuser ALL=(ALL) NOPASSWD:ALL for a single user, or
%sudo ALL=(ALL) NOPASSWD:ALL for a group.
Updated by François ARMAND over 5 years ago
- Assignee set to Félix DALLIDET
- Severity set to Critical - prevents main use of Rudder | no workaround | data loss | security
- User visibility set to Getting started - demo | first install | Technique editor and level 1 Techniques
- Priority changed from 0 to 93
Updated by François ARMAND over 5 years ago
- Severity changed from Critical - prevents main use of Rudder | no workaround | data loss | security to Minor - inconvenience | misleading | easy workaround
- Priority changed from 93 to 50
In fact, I misunderstood the problem: here, it asks for the password when it should not (so it's more minor than critical)
Updated by Félix DALLIDET over 5 years ago
- Status changed from New to In progress
Updated by Félix DALLIDET over 5 years ago
I was unable to reproduce on a debian9 platform, I tested it in 5.0.6 and 5.0.9.
Could you double check if the issue is still relevant? If so, could you describe precisely the steps and environment needed to reproduce.
Updated by Vincent MEMBRÉ over 5 years ago
- Target version changed from 5.0.10 to 5.0.11
- Priority changed from 50 to 49
Updated by Vincent MEMBRÉ over 5 years ago
- Target version changed from 5.0.11 to 5.0.12
Updated by Vincent MEMBRÉ over 5 years ago
- Target version changed from 5.0.12 to 5.0.13
- Priority changed from 49 to 48
Updated by Vincent MEMBRÉ about 5 years ago
- Target version changed from 5.0.13 to 5.0.14
- Priority changed from 48 to 47
Updated by Vincent MEMBRÉ about 5 years ago
- Target version changed from 5.0.14 to 5.0.15
- Priority changed from 47 to 46
Updated by Vincent MEMBRÉ almost 5 years ago
- Target version changed from 5.0.15 to 5.0.16
- Priority changed from 46 to 44
Updated by Alexis Mousset almost 5 years ago
- Target version changed from 5.0.16 to 5.0.17
- Priority changed from 44 to 42
Updated by Vincent MEMBRÉ over 4 years ago
- Target version changed from 5.0.17 to 5.0.18
Updated by Vincent MEMBRÉ over 4 years ago
- Target version changed from 5.0.18 to 5.0.19
Updated by Vincent MEMBRÉ about 4 years ago
- Target version changed from 5.0.19 to 5.0.20
Updated by Vincent MEMBRÉ about 4 years ago
- Target version changed from 5.0.20 to 797
Updated by Benoît PECCATTE over 3 years ago
- Target version changed from 797 to 6.1.14
Updated by Vincent MEMBRÉ over 3 years ago
- Target version changed from 6.1.14 to 6.1.15
Updated by Vincent MEMBRÉ over 3 years ago
- Target version changed from 6.1.15 to 6.1.16
Updated by Vincent MEMBRÉ about 3 years ago
- Target version changed from 6.1.16 to 6.1.17
Updated by Vincent MEMBRÉ about 3 years ago
- Target version changed from 6.1.17 to 6.1.18
Updated by Vincent MEMBRÉ almost 3 years ago
- Target version changed from 6.1.18 to 6.1.19
Updated by Alexis Mousset almost 3 years ago
- Status changed from In progress to New
Updated by Vincent MEMBRÉ over 2 years ago
- Target version changed from 6.1.19 to 6.1.20
- Priority changed from 42 to 43
Updated by Vincent MEMBRÉ over 2 years ago
- Target version changed from 6.1.20 to 6.1.21
Updated by Vincent MEMBRÉ over 2 years ago
- Target version changed from 6.1.21 to old 6.1 issues to relocate
- Priority changed from 43 to 44
Updated by Alexis Mousset 7 months ago
- Target version changed from old 6.1 issues to relocate to 7.3.15
- Priority changed from 44 to 0
Updated by Vincent MEMBRÉ 6 months ago
- Target version changed from 7.3.15 to 7.3.16
Updated by Vincent MEMBRÉ 5 months ago
- Target version changed from 7.3.16 to 7.3.17