[Fwd: [sudo-users] How to disable ( deny ) user to change the password of root]

edwardspl at ita.org.mo edwardspl at ita.org.mo
Mon Nov 17 09:25:00 UTC 2008


Dear All,

Just previewed the sudo manual :

http://www.sudo.ws/sudo/man/sudoers.html

pete           HPPA = /usr/bin/passwd [A-z]*, !/usr/bin/passwd root

The user pete is allowed to change anyone's password except for root on
the HPPA machines. Note that this assumes passwd(1) does not take
multiple usernames on the command line.

If the Linux System is FC System, so how about the format of it ?

Many thanks !

Edward.
-------- Original Message --------
Subject: 	[sudo-users] How to disable ( deny ) user to change the
password of root
Date: 	Mon, 17 Nov 2008 16:49:05 +0800
From: 	edwardspl at ita.org.mo
To: 	sudo-users at sudo.ws
CC: 	fedora-list at redhat.com <fedora-list at redhat.com>



Dear All,

For the sudo setting ( visudo ) :

User_Alias      SYSADM = manager

Cmnd_Alias    NOROOT = !/usr/bin/passwd root
Cmnd_Alias    USER = /usr/sbin/adduser, /usr/bin/passwd, /bin/chown, 
/usr/sbin/userdel

SYSADM    MH = (ALL)    NOROOT,USER

BUT the test result as the following :

[manager at xxx ~]$ sudo passwd root
Changing password for user root.
New UNIX password:

So, what wrong of the config ?

Many thnak for your hints...

Edward.
____________________________________________________________ 
sudo-users mailing list <sudo-users at sudo.ws>
For list information, options, or to unsubscribe, visit:
http://www.sudo.ws/mailman/listinfo/sudo-users

__________ NOD32 3616 (20081117) Information __________

This message was checked by NOD32 antivirus system.
http://www.nod32.com.hk




-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/fedora-list/attachments/20081117/18ed36c4/attachment-0001.htm>


More information about the fedora-list mailing list