sudo rules aren't matching as we expect - why not?

Solution Verified - Updated -

Environment

  • Red Hat Enterprise Linux 7, 8, 9, 10

Issue

We have sudo rules for a user like this:

testing ALL=NOPASSWD: /usr/bin/rm -rf /var/log/httpd/*

But the user isn't able to make use of the rules to do necessary work:

[testing@rhel9 httpd]$ pwd
/var/log/httpd
[testing@rhel9 httpd]$ sudo rm -rf testing
[sudo] password for testing: 
Sorry, user testing is not allowed to execute '/bin/rm -rf testing' as root on rhel9.

Resolution

You need to specify commands that exactly match the arguments allowed by sudo.

In the example given, the user is allowed to run rm -rf on /var/log/httpd/*.

Regardless of what directory that user is in, the command given must match. So in this case, the following command will work:

[testing@rhel9 httpd]$ sudo rm -rf /var/log/httpd/testing

Root Cause

The command given must match the command allowed by the sudo rules, and sudo will not ignore with the pathname requirement simply because the user is in the specified path already.

Diagnostic Steps

If your command is seemingly not being matched, verify:
- that your user is in the correct group
- that the arguments passed to the command match what's allowed

If the arguments the user is issuing are correct and the user should be allowed to issue them - verify by running sudo -l as the user - it might be worth looking at whether there's an issue with SELinux conflicting with sudo.
- See: Why does sudo fail with SElinux user user_u ?

This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.

Comments