Allow sudo su - only to one user












0















Allow sudo su - on visudo only to one or some users of a group that access by ldap



For example, I have visually defined the following:



% dev ALL = (ALL) ALL


What I need is that only some users or only one of the dev group can do the sudo su -, not all of the group ... is it possible to do this?










share|improve this question

























  • Can you create a new group?

    – kemotep
    Feb 21 at 16:40











  • Just use username instead of %dev. eg I have sweh ALL=(ALL) ALL on my machine to allow the user "sweh" all commands.

    – Stephen Harris
    Feb 21 at 16:42






  • 1





    Related to sudo su -: Is there ever a good reason to run sudo su?

    – Kusalananda
    Feb 21 at 17:35













  • yes but in my case I need the sweh user to be in the group% dev which is authenticated by openldap

    – miguel ramires
    Feb 21 at 21:45
















0















Allow sudo su - on visudo only to one or some users of a group that access by ldap



For example, I have visually defined the following:



% dev ALL = (ALL) ALL


What I need is that only some users or only one of the dev group can do the sudo su -, not all of the group ... is it possible to do this?










share|improve this question

























  • Can you create a new group?

    – kemotep
    Feb 21 at 16:40











  • Just use username instead of %dev. eg I have sweh ALL=(ALL) ALL on my machine to allow the user "sweh" all commands.

    – Stephen Harris
    Feb 21 at 16:42






  • 1





    Related to sudo su -: Is there ever a good reason to run sudo su?

    – Kusalananda
    Feb 21 at 17:35













  • yes but in my case I need the sweh user to be in the group% dev which is authenticated by openldap

    – miguel ramires
    Feb 21 at 21:45














0












0








0








Allow sudo su - on visudo only to one or some users of a group that access by ldap



For example, I have visually defined the following:



% dev ALL = (ALL) ALL


What I need is that only some users or only one of the dev group can do the sudo su -, not all of the group ... is it possible to do this?










share|improve this question
















Allow sudo su - on visudo only to one or some users of a group that access by ldap



For example, I have visually defined the following:



% dev ALL = (ALL) ALL


What I need is that only some users or only one of the dev group can do the sudo su -, not all of the group ... is it possible to do this?







security sudo openldap






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Feb 21 at 16:42









Stephen Harris

26.5k34780




26.5k34780










asked Feb 21 at 16:32









miguel ramiresmiguel ramires

1




1













  • Can you create a new group?

    – kemotep
    Feb 21 at 16:40











  • Just use username instead of %dev. eg I have sweh ALL=(ALL) ALL on my machine to allow the user "sweh" all commands.

    – Stephen Harris
    Feb 21 at 16:42






  • 1





    Related to sudo su -: Is there ever a good reason to run sudo su?

    – Kusalananda
    Feb 21 at 17:35













  • yes but in my case I need the sweh user to be in the group% dev which is authenticated by openldap

    – miguel ramires
    Feb 21 at 21:45



















  • Can you create a new group?

    – kemotep
    Feb 21 at 16:40











  • Just use username instead of %dev. eg I have sweh ALL=(ALL) ALL on my machine to allow the user "sweh" all commands.

    – Stephen Harris
    Feb 21 at 16:42






  • 1





    Related to sudo su -: Is there ever a good reason to run sudo su?

    – Kusalananda
    Feb 21 at 17:35













  • yes but in my case I need the sweh user to be in the group% dev which is authenticated by openldap

    – miguel ramires
    Feb 21 at 21:45

















Can you create a new group?

– kemotep
Feb 21 at 16:40





Can you create a new group?

– kemotep
Feb 21 at 16:40













Just use username instead of %dev. eg I have sweh ALL=(ALL) ALL on my machine to allow the user "sweh" all commands.

– Stephen Harris
Feb 21 at 16:42





Just use username instead of %dev. eg I have sweh ALL=(ALL) ALL on my machine to allow the user "sweh" all commands.

– Stephen Harris
Feb 21 at 16:42




1




1





Related to sudo su -: Is there ever a good reason to run sudo su?

– Kusalananda
Feb 21 at 17:35







Related to sudo su -: Is there ever a good reason to run sudo su?

– Kusalananda
Feb 21 at 17:35















yes but in my case I need the sweh user to be in the group% dev which is authenticated by openldap

– miguel ramires
Feb 21 at 21:45





yes but in my case I need the sweh user to be in the group% dev which is authenticated by openldap

– miguel ramires
Feb 21 at 21:45










0






active

oldest

votes











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "106"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f502120%2fallow-sudo-su-only-to-one-user%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Unix & Linux Stack Exchange!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f502120%2fallow-sudo-su-only-to-one-user%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

How to reconfigure Docker Trusted Registry 2.x.x to use CEPH FS mount instead of NFS and other traditional...

is 'sed' thread safe

How to make a Squid Proxy server?