how to enforce password in sudoers configuration for user that doesn't have password set?

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
1
down vote

favorite












I have a group of users (wheel for example) that I want to add to /etc/sudoers for all commands i.e.:



%wheel ALL=(ALL) ALL



In this scenario, if users are set up correctly, everyone in wheel will be prompted for password upon trying to use an elevated command. For any user that does not have a password set (via /etc/shadow), the user will not be prompted for a password and command will succeed....this presents a problem for me. I do not want users with no passwords set to be able to succeed in doing this.



I cannot find a possible way, specifically just through /etc/sudoers, to make any elevated command fail with users with no passwords set. Let me know if I am missing something...



And yes, I know I can approach the problem differently outside of /etc/sudoers (chicken and egg) and know of ways to do it...not question of that though. Any tips would be greatly appreciated!










share|improve this question





















  • decided to be enforced with some pam module configuration
    – blieberman
    Sep 27 '17 at 15:41














up vote
1
down vote

favorite












I have a group of users (wheel for example) that I want to add to /etc/sudoers for all commands i.e.:



%wheel ALL=(ALL) ALL



In this scenario, if users are set up correctly, everyone in wheel will be prompted for password upon trying to use an elevated command. For any user that does not have a password set (via /etc/shadow), the user will not be prompted for a password and command will succeed....this presents a problem for me. I do not want users with no passwords set to be able to succeed in doing this.



I cannot find a possible way, specifically just through /etc/sudoers, to make any elevated command fail with users with no passwords set. Let me know if I am missing something...



And yes, I know I can approach the problem differently outside of /etc/sudoers (chicken and egg) and know of ways to do it...not question of that though. Any tips would be greatly appreciated!










share|improve this question





















  • decided to be enforced with some pam module configuration
    – blieberman
    Sep 27 '17 at 15:41












up vote
1
down vote

favorite









up vote
1
down vote

favorite











I have a group of users (wheel for example) that I want to add to /etc/sudoers for all commands i.e.:



%wheel ALL=(ALL) ALL



In this scenario, if users are set up correctly, everyone in wheel will be prompted for password upon trying to use an elevated command. For any user that does not have a password set (via /etc/shadow), the user will not be prompted for a password and command will succeed....this presents a problem for me. I do not want users with no passwords set to be able to succeed in doing this.



I cannot find a possible way, specifically just through /etc/sudoers, to make any elevated command fail with users with no passwords set. Let me know if I am missing something...



And yes, I know I can approach the problem differently outside of /etc/sudoers (chicken and egg) and know of ways to do it...not question of that though. Any tips would be greatly appreciated!










share|improve this question













I have a group of users (wheel for example) that I want to add to /etc/sudoers for all commands i.e.:



%wheel ALL=(ALL) ALL



In this scenario, if users are set up correctly, everyone in wheel will be prompted for password upon trying to use an elevated command. For any user that does not have a password set (via /etc/shadow), the user will not be prompted for a password and command will succeed....this presents a problem for me. I do not want users with no passwords set to be able to succeed in doing this.



I cannot find a possible way, specifically just through /etc/sudoers, to make any elevated command fail with users with no passwords set. Let me know if I am missing something...



And yes, I know I can approach the problem differently outside of /etc/sudoers (chicken and egg) and know of ways to do it...not question of that though. Any tips would be greatly appreciated!







linux shell sudo users authentication






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Sep 26 '17 at 22:11









blieberman

62




62











  • decided to be enforced with some pam module configuration
    – blieberman
    Sep 27 '17 at 15:41
















  • decided to be enforced with some pam module configuration
    – blieberman
    Sep 27 '17 at 15:41















decided to be enforced with some pam module configuration
– blieberman
Sep 27 '17 at 15:41




decided to be enforced with some pam module configuration
– blieberman
Sep 27 '17 at 15:41















active

oldest

votes











Your Answer







StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "106"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
convertImagesToLinks: false,
noModals: false,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













 

draft saved


draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f394643%2fhow-to-enforce-password-in-sudoers-configuration-for-user-that-doesnt-have-pass%23new-answer', 'question_page');

);

Post as a guest



































active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes















 

draft saved


draft discarded















































 


draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f394643%2fhow-to-enforce-password-in-sudoers-configuration-for-user-that-doesnt-have-pass%23new-answer', 'question_page');

);

Post as a guest













































































Popular posts from this blog

Peggy Mitchell

Palaiologos

The Forum (Inglewood, California)