[sudo-users] Clarification of sudoers manual requested: multiple matches in sudoers file

christian.peper at kpn.com christian.peper at kpn.com
Mon Dec 10 11:25:34 EST 2007


Dear all,

I have a small issue with the sudoers manual about multiple matches and
how that's handled. It concerns the 2nd paragraph in the section
"Description".
http://www.gratisoft.us/sudo/man/sudoers.html

The manual lists:
"When multiple entries match for a user, they are applied in order.
Where there are multiple matches, the last match is used (which is not
necessarily the most specific match)."

Could someone elaborate on this?
What exactly is the difference between 'multiple entries' and 'multiple
matches'?
How does this affect the order I must use when building a sudoers file?

I have some users who belong to the groups users, sysop and dba and I'm
going crazy trying to figure out which line exactly grants or denies
permission on specific commands.

Much appreciated!
Chris.



More information about the sudo-users mailing list