sudoers line for sudo user with /bin/su command or runas or /bin/bash

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
0
down vote

favorite












What is the difference between these three sudoers line and which one is more secure and auditable? End goal is anyone in the group 'sudogroup' group should be able to sudo to user 'swuser' or run as 'swuser' commands without asking for a password.



%sudogroup ALL=(root) NOPASSWD: /bin/su - swuser

%sudogroup ALL=(swuser) NOPASSWD:ALL

%sudogroup ALL=(swuser) NOPASSWD: /bin/bash


This question may be complement to su vs sudo -s vs sudo -i vs sudo bash
OR
What does "sudo su -s /bin/bash - <username>" do?










share|improve this question









New contributor




yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.



















  • Is this a test question, or are you considering one of these for production use?
    – Jeff Schaller
    2 mins ago














up vote
0
down vote

favorite












What is the difference between these three sudoers line and which one is more secure and auditable? End goal is anyone in the group 'sudogroup' group should be able to sudo to user 'swuser' or run as 'swuser' commands without asking for a password.



%sudogroup ALL=(root) NOPASSWD: /bin/su - swuser

%sudogroup ALL=(swuser) NOPASSWD:ALL

%sudogroup ALL=(swuser) NOPASSWD: /bin/bash


This question may be complement to su vs sudo -s vs sudo -i vs sudo bash
OR
What does "sudo su -s /bin/bash - <username>" do?










share|improve this question









New contributor




yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.



















  • Is this a test question, or are you considering one of these for production use?
    – Jeff Schaller
    2 mins ago












up vote
0
down vote

favorite









up vote
0
down vote

favorite











What is the difference between these three sudoers line and which one is more secure and auditable? End goal is anyone in the group 'sudogroup' group should be able to sudo to user 'swuser' or run as 'swuser' commands without asking for a password.



%sudogroup ALL=(root) NOPASSWD: /bin/su - swuser

%sudogroup ALL=(swuser) NOPASSWD:ALL

%sudogroup ALL=(swuser) NOPASSWD: /bin/bash


This question may be complement to su vs sudo -s vs sudo -i vs sudo bash
OR
What does "sudo su -s /bin/bash - <username>" do?










share|improve this question









New contributor




yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.











What is the difference between these three sudoers line and which one is more secure and auditable? End goal is anyone in the group 'sudogroup' group should be able to sudo to user 'swuser' or run as 'swuser' commands without asking for a password.



%sudogroup ALL=(root) NOPASSWD: /bin/su - swuser

%sudogroup ALL=(swuser) NOPASSWD:ALL

%sudogroup ALL=(swuser) NOPASSWD: /bin/bash


This question may be complement to su vs sudo -s vs sudo -i vs sudo bash
OR
What does "sudo su -s /bin/bash - <username>" do?







security sudo su






share|improve this question









New contributor




yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.











share|improve this question









New contributor




yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









share|improve this question




share|improve this question








edited 2 mins ago









Jeff Schaller

35.4k952116




35.4k952116






New contributor




yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









asked 14 mins ago









yman

1




1




New contributor




yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.





New contributor





yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.






yman is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.











  • Is this a test question, or are you considering one of these for production use?
    – Jeff Schaller
    2 mins ago
















  • Is this a test question, or are you considering one of these for production use?
    – Jeff Schaller
    2 mins ago















Is this a test question, or are you considering one of these for production use?
– Jeff Schaller
2 mins ago




Is this a test question, or are you considering one of these for production use?
– Jeff Schaller
2 mins ago















active

oldest

votes











Your Answer








StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "106"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);






yman is a new contributor. Be nice, and check out our Code of Conduct.









 

draft saved


draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f480423%2fsudoers-line-for-sudo-user-with-bin-su-command-or-runas-or-bin-bash%23new-answer', 'question_page');

);

Post as a guest



































active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes








yman is a new contributor. Be nice, and check out our Code of Conduct.









 

draft saved


draft discarded


















yman is a new contributor. Be nice, and check out our Code of Conduct.












yman is a new contributor. Be nice, and check out our Code of Conduct.











yman is a new contributor. Be nice, and check out our Code of Conduct.













 


draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f480423%2fsudoers-line-for-sudo-user-with-bin-su-command-or-runas-or-bin-bash%23new-answer', 'question_page');

);

Post as a guest













































































Popular posts from this blog

Peggy Mitchell

Palaiologos

The Forum (Inglewood, California)