suder line for sudo user with /bin/su command or runas or /bin/bash

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
0
down vote

favorite












What is the difference between these three sudoer line and which one is more secure and auditable ? End goal is anyone in the group 'sudogroup' group should be able to sudo to user 'swuser' or run as 'swuser' commands without asking password



%sudogroup ALL=(root) NOPASSWD: /bin/su - swuser



%sudogroup ALL=(swuser) NOPASSWD:ALL



%sudogroup ALL=(swuser) NOPASSWD: /bin/bash



This question may be complement to su vs sudo -s vs sudo -i vs sudo bash
OR
What does "sudo su -s /bin/bash - <username>" do?









share









New contributor




yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.























    up vote
    0
    down vote

    favorite












    What is the difference between these three sudoer line and which one is more secure and auditable ? End goal is anyone in the group 'sudogroup' group should be able to sudo to user 'swuser' or run as 'swuser' commands without asking password



    %sudogroup ALL=(root) NOPASSWD: /bin/su - swuser



    %sudogroup ALL=(swuser) NOPASSWD:ALL



    %sudogroup ALL=(swuser) NOPASSWD: /bin/bash



    This question may be complement to su vs sudo -s vs sudo -i vs sudo bash
    OR
    What does "sudo su -s /bin/bash - <username>" do?









    share









    New contributor




    yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
    Check out our Code of Conduct.





















      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      What is the difference between these three sudoer line and which one is more secure and auditable ? End goal is anyone in the group 'sudogroup' group should be able to sudo to user 'swuser' or run as 'swuser' commands without asking password



      %sudogroup ALL=(root) NOPASSWD: /bin/su - swuser



      %sudogroup ALL=(swuser) NOPASSWD:ALL



      %sudogroup ALL=(swuser) NOPASSWD: /bin/bash



      This question may be complement to su vs sudo -s vs sudo -i vs sudo bash
      OR
      What does "sudo su -s /bin/bash - <username>" do?









      share









      New contributor




      yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.











      What is the difference between these three sudoer line and which one is more secure and auditable ? End goal is anyone in the group 'sudogroup' group should be able to sudo to user 'swuser' or run as 'swuser' commands without asking password



      %sudogroup ALL=(root) NOPASSWD: /bin/su - swuser



      %sudogroup ALL=(swuser) NOPASSWD:ALL



      %sudogroup ALL=(swuser) NOPASSWD: /bin/bash



      This question may be complement to su vs sudo -s vs sudo -i vs sudo bash
      OR
      What does "sudo su -s /bin/bash - <username>" do?







      security sudo su





      share









      New contributor




      yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.










      share









      New contributor




      yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.








      share



      share








      edited 1 min ago









      Jeff Schaller

      35.4k952116




      35.4k952116






      New contributor




      yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      asked 3 mins ago









      yman

      1




      1




      New contributor




      yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.





      New contributor





      yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.






      yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.

























          active

          oldest

          votes











          Your Answer








          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "106"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          convertImagesToLinks: false,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: null,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );






          yman is a new contributor. Be nice, and check out our Code of Conduct.









           

          draft saved


          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f480423%2fsuder-line-for-sudo-user-with-bin-su-command-or-runas-or-bin-bash%23new-answer', 'question_page');

          );

          Post as a guest



































          active

          oldest

          votes













          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes








          yman is a new contributor. Be nice, and check out our Code of Conduct.









           

          draft saved


          draft discarded


















          yman is a new contributor. Be nice, and check out our Code of Conduct.












          yman is a new contributor. Be nice, and check out our Code of Conduct.











          yman is a new contributor. Be nice, and check out our Code of Conduct.













           


          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f480423%2fsuder-line-for-sudo-user-with-bin-su-command-or-runas-or-bin-bash%23new-answer', 'question_page');

          );

          Post as a guest













































































          Popular posts from this blog

          Peggy Mitchell

          Palaiologos

          The Forum (Inglewood, California)