[sudo-users] audit of sudo

Brown, Eugene Eugene.Brown at experian.com
Fri Dec 2 17:23:56 EST 2005


Is there a method to audit sudo to ensure that scripts placed in sudo to
run as root are owned by root and are not writable by others?

Is there a "pseudo" shell that would run a script, resolve all
variables, but only list what is to be run but not actually run the
commands?

Has there been any discussion on using include files in /etc/sudoers? Or
using directives? This would allow the main file to remain smaller and
have platform specific rules in an include file based off a directive.

Eugene Brown
UNIX Systems Administration
972-390-3322




More information about the sudo-users mailing list