{"id":16945,"date":"2025-02-21T09:22:22","date_gmt":"2025-02-21T01:22:22","guid":{"rendered":"https:\/\/92it.top\/?p=16945"},"modified":"2025-02-21T09:22:22","modified_gmt":"2025-02-21T01:22:22","slug":"linux%e7%9a%84sudo%e6%8c%87%e4%bb%a4%ef%bc%8c%e8%83%8c%e5%90%8e%e5%81%9a%e4%ba%86%e4%bb%80%e4%b9%88%ef%bc%9f","status":"publish","type":"post","link":"https:\/\/92it.top\/?p=16945","title":{"rendered":"Linux\u7684sudo\u6307\u4ee4\uff0c\u80cc\u540e\u505a\u4e86\u4ec0\u4e48\uff1f"},"content":{"rendered":"\n<p>\u8f6c\u8f7d\uff1aLinux\u7684sudo\u6307\u4ee4\uff0c\u80cc\u540e\u505a\u4e86\u4ec0\u4e48\uff1f<\/p>\n\n\n\n<p>\u5728\u5b9e\u9645\u5de5\u4f5c\u4e2d\uff0c\u6211\u4eec\u7ecf\u5e38\u4f7f\u7528 Linux\u7684<code>sudo<\/code>\u6307\u4ee4\u8fdb\u884c\u64cd\u4f5c\u3002\u90a3\u4e48\uff0c<code>sudo<\/code>\u662f\u4ec0\u4e48\uff1f\u5b83\u80cc\u540e\u505a\u4e86\u4ec0\u4e48\uff1f\u4e3a\u4ec0\u4e48\u4f7f\u7528<code>sudo<\/code>\u800c\u4e0d\u662f\u76f4\u63a5\u4f7f\u7528<code>root<\/code>\uff0c\u5b83\u5bf9\u5b89\u5168\u6027\u6709\u4ec0\u4e48\u5f71\u54cd\uff1f\u8fd9\u7bc7\u6587\u7ae0\uff0c\u6211\u4eec\u5c06\u5168\u9762\u5206\u6790<code>sudo<\/code><\/p>\n\n\n\n<p><strong>1. \u4ec0\u4e48\u662fsudo\uff1f<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><code>sudo<\/code>\uff08superuser do\u7684\u7f29\u5199\uff09\u662f\u4e00\u4e2a\u5141\u8bb8\u6388\u6743\u7528\u6237\u4ee5\u522b\u7684\u7528\u6237\u8eab\u4efd\uff08\u901a\u5e38\u662froot\uff09\u8fd0\u884c\u7a0b\u5e8f\u7684\u7a0b\u5e8f\u3002\u5b83\u6700\u521d\u7531Bob Coggeshall\u548cCliff Spencer\u57281980\u5e74\u4ee3\u5f00\u53d1\uff0c\u65e8\u5728\u63d0\u4f9b\u4e00\u79cd\u6bd4\u4f20\u7edf\u7684su\uff08\u5207\u6362\u7528\u6237\uff09\u66f4\u5b89\u5168\u3001\u66f4\u7075\u6d3b\u7684\u6743\u9650\u7ba1\u7406\u65b9\u5f0f\u3002<\/p>\n\n\n\n<p><strong>2. \u4e3a\u4ec0\u4e48\u4f7f\u7528 sudo\u800c\u4e0d\u662f\u76f4\u63a5\u4f7f\u7528root\uff1f<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>\u76f4\u63a5\u4f7f\u7528<code>root<\/code>\u8d26\u6237\u5b58\u5728\u8bf8\u591a\u98ce\u9669\uff1a<\/p>\n\n\n\n<ul>\n<li><strong>\u5b89\u5168\u6027<\/strong>\uff1a<code>root<\/code>\u8d26\u6237\u7f3a\u4e4f\u4fdd\u62a4\uff0c\u4e00\u65e6\u6cc4\u9732\uff0c\u653b\u51fb\u8005\u5c06\u62e5\u6709\u7cfb\u7edf\u7684\u5b8c\u5168\u63a7\u5236\u6743\u3002<\/li>\n\n\n\n<li><strong>\u5ba1\u8ba1\u548c\u65e5\u5fd7<\/strong>\uff1a\u901a\u8fc7<code>root<\/code>\u6267\u884c\u7684\u64cd\u4f5c\u96be\u4ee5\u8ffd\u8e2a\u6765\u6e90\uff0c\u4e0d\u5229\u4e8e\u5ba1\u8ba1\u548c\u95ee\u9898\u6392\u67e5\u3002<\/li>\n\n\n\n<li><strong>\u8bef\u64cd\u4f5c\u98ce\u9669<\/strong>\uff1a\u957f\u671f\u4f7f\u7528<code>root<\/code>\u8d26\u6237\u5bb9\u6613\u5bfc\u81f4\u8bef\u64cd\u4f5c\uff0c\u53ef\u80fd\u5bf9\u7cfb\u7edf\u9020\u6210\u4e0d\u53ef\u9006\u8f6c\u7684\u635f\u5bb3\u3002<\/li>\n<\/ul>\n\n\n\n<p><code>sudo<\/code>\u901a\u8fc7\u4ee5\u4e0b\u65b9\u5f0f\u7f13\u89e3\u4e0a\u8ff0\u95ee\u9898\uff1a<\/p>\n\n\n\n<ul>\n<li><strong>\u6700\u5c0f\u6743\u9650\u539f\u5219<\/strong>\uff1a\u4ec5\u6388\u4e88\u5fc5\u8981\u7684\u6743\u9650\uff0c\u51cf\u5c11\u8bef\u64cd\u4f5c\u548c\u6f5c\u5728\u7684\u5b89\u5168\u98ce\u9669\u3002<\/li>\n\n\n\n<li><strong>\u65e5\u5fd7\u8bb0\u5f55<\/strong>\uff1a\u6240\u6709\u4f7f\u7528sudo\u6267\u884c\u7684\u547d\u4ee4\u90fd\u4f1a\u88ab\u8bb0\u5f55\uff0c\u4fbf\u4e8e\u5ba1\u8ba1\u548c\u8ffd\u8e2a\u3002<\/li>\n\n\n\n<li><strong>\u7ec6\u7c92\u5ea6\u63a7\u5236<\/strong>\uff1a\u53ef\u4ee5\u9488\u5bf9\u4e0d\u540c\u7528\u6237\u6216\u7528\u6237\u7ec4\uff0c\u8bbe\u7f6e\u4e0d\u540c\u7684\u6743\u9650\u89c4\u5219\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>3. \u57fa\u672c\u7528\u6cd5<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>3.1 \u57fa\u672c\u8bed\u6cd5<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo [\u9009\u9879] \u547d\u4ee4\n<\/pre>\n\n\n\n<p><strong>\u5e38\u7528\u9009\u9879:<\/strong><\/p>\n\n\n\n<ul>\n<li><code>-u \u7528\u6237<\/code>\uff1a\u4ee5\u6307\u5b9a\u7528\u6237\u7684\u8eab\u4efd\u8fd0\u884c\u547d\u4ee4\uff0c\u9ed8\u8ba4\u4e3aroot\u3002<\/li>\n\n\n\n<li><code>-s<\/code>\uff1a\u4ee5shell\u5f62\u5f0f\u8fd0\u884c\u547d\u4ee4\u3002<\/li>\n\n\n\n<li><code>-i<\/code>\uff1a\u6a21\u62df\u5b8c\u6574\u7684\u767b\u5f55\u73af\u5883\u3002<\/li>\n\n\n\n<li><code>-k<\/code>\uff1a\u65e0\u89c6\u548c\u6e05\u9664\u4e4b\u524d\u7684\u8ba4\u8bc1\u7f13\u5b58\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>3.2 \u4f7f\u7528\u793a\u4f8b<\/strong><\/p>\n\n\n\n<p><strong>\u4ee5root\u8eab\u4efd\u6267\u884c\u547d\u4ee4<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo apt update\nsudo yum install nginx\n<\/pre>\n\n\n\n<p><strong>\u4ee5\u5176\u4ed6\u7528\u6237\u8eab\u4efd\u6267\u884c\u547d\u4ee4<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo -u www-data ls \/var\/www\n<\/pre>\n\n\n\n<p><strong>\u4ee5shell\u5f62\u5f0f\u5207\u6362\u5230root<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo -s\n<\/pre>\n\n\n\n<p><strong>\u4ee5\u767b\u5f55shell\u5f62\u5f0f\u5207\u6362\u5230\u6307\u5b9a\u7528\u6237<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo -i -u username\n<\/pre>\n\n\n\n<p><strong>4. \u914d\u7f6esudo<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><code>sudo<\/code>\u7684\u884c\u4e3a\u548c\u6743\u9650\u7531<code>\/etc\/sudoers<\/code>\u6587\u4ef6\u63a7\u5236\u3002\u76f4\u63a5\u7f16\u8f91\u6b64\u6587\u4ef6\u5b58\u5728\u98ce\u9669\uff0c\u4e3a\u907f\u514d\u8bed\u6cd5\u9519\u8bef\u5bfc\u81f4\u7684\u7cfb\u7edf\u95ee\u9898\uff0c\u5efa\u8bae\u4f7f\u7528<code>visudo<\/code>\u547d\u4ee4\u8fdb\u884c\u7f16\u8f91\u3002<\/p>\n\n\n\n<p>sudoers\u6587\u4ef6\u4e3b\u8981\u7531\u4ee5\u4e0b\u90e8\u5206\u7ec4\u6210\uff1a<\/p>\n\n\n\n<ul>\n<li><strong>\u522b\u540d\u5b9a\u4e49<\/strong>\uff1a\u5b9a\u4e49\u7528\u6237\u3001\u4e3b\u673a\u3001\u547d\u4ee4\u7b49\u522b\u540d\uff0c\u4fbf\u4e8e\u7ba1\u7406\u3002<\/li>\n\n\n\n<li><strong>\u6743\u9650\u89c4\u5219<\/strong>\uff1a\u6307\u5b9a\u54ea\u4e9b\u7528\u6237\u6216\u7528\u6237\u7ec4\u53ef\u4ee5\u6267\u884c\u54ea\u4e9b\u547d\u4ee4\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>4.1 \u522b\u540d\u5b9a\u4e49<\/strong><\/p>\n\n\n\n<p>\u522b\u540d\u5b9a\u4e49\u5305\u62ec\u7528\u6237\u522b\u540d\uff0c\u4e3b\u673a\u522b\u540d\u548c\u547d\u4ee4\u522b\u540d\u3002<\/p>\n\n\n\n<p>User_Alias\uff1a\u5b9a\u4e49\u7528\u6237\u522b\u540d\u3002\u5982\u4e0b\u793a\u4f8b\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">User_Alias ADMINS = alice, bob\n<\/pre>\n\n\n\n<p>HOST_Alias\uff1a\u5b9a\u4e49\u4e3b\u673a\u522b\u540d\u3002\u5982\u4e0b\u793a\u4f8b\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">Host_Alias SERVER = server1, server2\n<\/pre>\n\n\n\n<p>COMMAND_Alias\uff1a\u5b9a\u4e49\u547d\u4ee4\u522b\u540d\u3002\u5982\u4e0b\u793a\u4f8b\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">Cmnd_Alias WEB_CMDS = \/usr\/bin\/systemctl start nginx, \/usr\/bin\/systemctl stop nginx\n<\/pre>\n\n\n\n<p><strong>4.2 \u6743\u9650\u89c4\u5219<\/strong><\/p>\n\n\n\n<p>\u6743\u9650\u89c4\u5219\u6307\u5b9a\u54ea\u4e9b\u7528\u6237\u53ef\u4ee5\u5728\u7279\u5b9a\u4e3b\u673a\u4e0a\u6267\u884c\u7279\u5b9a\u547d\u4ee4\uff0c\u4ee5\u4f55\u79cd\u65b9\u5f0f\u6267\u884c\u3002<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\"># \u683c\u5f0f\n\u7528\u6237 \u522b\u540d = (\u8fd0\u884c\u8eab\u4efd) \u547d\u4ee4\u522b\u540d\n\n# \u793a\u4f8b\uff1a\u5141\u8bb8\u7528\u6237alice\u5728\u4e3b\u673aSERVER\u4e0a\u4ee5root\u8eab\u4efd\u6267\u884cWEB_CMDS\u4e2d\u7684\u547d\u4ee4\uff0c\u800c\u4e14\u65e0\u9700\u8f93\u5165\u5bc6\u7801\u3002\nalice SERVER = (root) NOPASSWD: WEB_CMDS\n<\/pre>\n\n\n\n<p><strong>4.3 \u5e38\u89c1\u914d\u7f6e\u793a\u4f8b<\/strong><\/p>\n\n\n\n<p><strong>\u5141\u8bb8\u7528\u6237\u7ec4sudo\u6267\u884c\u4efb\u4f55\u547d\u4ee4<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">%sudo ALL=(ALL:ALL) ALL\n<\/pre>\n\n\n\n<p>\u5176\u4e2d\uff0c<code>%sudo<\/code>\u8868\u793a\u7528\u6237\u7ec4sudo\uff0c<code>ALL<\/code>\u8868\u793a\u6240\u6709\u4e3b\u673a\uff0c<code>(ALL:ALL)<\/code>\u8868\u793a\u4ee5\u6240\u6709\u7528\u6237\u548c\u7ec4\u8eab\u4efd\u8fd0\u884c\uff0c\u6700\u540e\u7684<code>ALL<\/code>\u8868\u793a\u6240\u6709\u547d\u4ee4\u3002<\/p>\n\n\n\n<p><strong>\u5141\u8bb8\u7279\u5b9a\u7528\u6237\u6267\u884c\u7279\u5b9a\u547d\u4ee4<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">john ALL=(ALL) \/usr\/bin\/systemctl restart nginx, \/usr\/bin\/systemctl status nginx\n<\/pre>\n\n\n\n<p>\u4e0a\u8ff0\u89c4\u5219\u5141\u8bb8\u7528\u6237john\u5728\u6240\u6709\u4e3b\u673a\u4e0a\u4ee5\u4efb\u4f55\u7528\u6237\u8eab\u4efd\u6267\u884c<code>systemctl restart nginx<\/code>\u548c<code>systemctl status nginx<\/code>\u547d\u4ee4\u3002<\/p>\n\n\n\n<p><strong>\u5141\u8bb8\u7528\u6237\u65e0\u9700\u8f93\u5165\u5bc6\u7801\u6267\u884c\u547d\u4ee4<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">jane ALL=(ALL) NOPASSWD: \/usr\/bin\/apt update, \/usr\/bin\/apt upgrade\n<\/pre>\n\n\n\n<p>\u8fd9\u6837\u914d\u7f6e\u540e\uff0c\u7528\u6237jane\u65e0\u9700\u8f93\u5165\u5bc6\u7801\u5373\u53ef\u6267\u884c<code>apt update<\/code>\u548c<code>apt upgrade<\/code>\u547d\u4ee4\u3002<\/p>\n\n\n\n<p><strong>5. \u7ba1\u7406sudo\u6743\u9650<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>5.1 \u6dfb\u52a0\u7528\u6237\u5230sudo\u7ec4<\/strong><\/p>\n\n\n\n<p>\u5728\u8bb8\u591a Linux\u53d1\u884c\u7248\u4e2d\uff0c\u9ed8\u8ba4\u7684<code>sudo<\/code>\u6743\u9650\u662f\u6388\u4e88\u7279\u5b9a\u7528\u6237\u7ec4\uff08\u5982 sudo\u6216 wheel\uff09\u3002\u901a\u8fc7\u5c06\u7528\u6237\u6dfb\u52a0\u5230\u76f8\u5e94\u7684\u7ec4\uff0c\u53ef\u4ee5\u8d4b\u4e88\u5176<code>sudo<\/code>\u6743\u9650\u3002<\/p>\n\n\n\n<p><strong>\u5728Debian\/Ubuntu\u4e0a\u5c06\u7528\u6237\u6dfb\u52a0\u5230sudo\u7ec4<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo usermod -aG sudo username\n<\/pre>\n\n\n\n<p><strong>\u5728Red Hat\/CentOS\/Fedora\u4e0a\u5c06\u7528\u6237\u6dfb\u52a0\u5230wheel\u7ec4<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo usermod -aG wheel username\n<\/pre>\n\n\n\n<p><strong>\u521b\u5efa\u81ea\u5b9a\u4e49\u7528\u6237\u7ec4<\/strong><\/p>\n\n\n\n<p>\u6709\u65f6\uff0c\u9700\u8981\u4e3a\u4e0d\u540c\u7684\u6743\u9650\u9700\u6c42\u521b\u5efa\u4e13\u95e8\u7684\u7528\u6237\u7ec4\u3002\u53ef\u4ee5\u6309\u7167\u4e0b\u9762\u7684\u65b9\u5f0f\u6765\u5b9e\u73b0\uff1a<\/p>\n\n\n\n<p><strong>1. \u521b\u5efa\u4e00\u4e2a\u65b0\u7ec4<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo groupadd devadmins\n<\/pre>\n\n\n\n<p><strong>2. \u5c06\u7528\u6237\u6dfb\u52a0\u5230\u65b0\u7ec4<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo usermod -aG devadmins username\n<\/pre>\n\n\n\n<p><strong>3. \u5728sudoers\u6587\u4ef6\u4e2d\u914d\u7f6e\u65b0\u7ec4\u7684\u6743\u9650<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">%devadmins ALL=(ALL) \/usr\/bin\/systemctl, \/usr\/bin\/apt\n<\/pre>\n\n\n\n<p><strong>5.2 \u79fb\u9664\u7528\u6237\u7684sudo\u6743\u9650<\/strong><\/p>\n\n\n\n<p>\u8981\u79fb\u9664\u7528\u6237\u7684sudo\u6743\u9650\uff0c\u53ef\u4ee5\u5c06\u5176\u4ecesudo\u7ec4\uff08\u6216\u76f8\u5e94\u7684\u6743\u9650\u7ec4\uff09\u4e2d\u79fb\u9664\u3002<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo deluser username sudo  # Debian\/Ubuntu\nsudo gpasswd -d username wheel  # Red Hat\/CentOS\/Fedora\n<\/pre>\n\n\n\n<p><strong>6. sudo\u9ad8\u7ea7\u529f\u80fd<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>6.1 sudoers\u4e2d\u7684\u522b\u540d<\/strong><\/p>\n\n\n\n<p>\u522b\u540d\u4f7f\u5f97sudoers\u6587\u4ef6\u66f4\u5177\u53ef\u8bfb\u6027\u548c\u53ef\u7ef4\u62a4\u6027\u3002\u5229\u7528User_Alias\u3001Host_Alias\u548cCommand_Alias\uff0c\u53ef\u4ee5\u5c06\u590d\u6742\u7684\u6743\u9650\u89c4\u5219\u7b80\u5316\u4e3a\u7b80\u6d01\u7684\u914d\u7f6e\u3002<\/p>\n\n\n\n<p><strong>6.2 \u7ec4\u5408\u4f7f\u7528\u522b\u540d<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">User_Alias ADMINS = alice, bob\nHost_Alias DATABASE_SERVERS = db1, db2\nCmnd_Alias DB_CMDS = \/usr\/bin\/mysql, \/usr\/bin\/mysqldump\n\nADMINS DATABASE_SERVERS = (dbadmin) DB_CMDS\n<\/pre>\n\n\n\n<p>\u4e0a\u8ff0\u914d\u7f6e\u5141\u8bb8ADMINS\u7ec4\u4e2d\u7684\u7528\u6237\u5728DATABASE_SERVERS\u4e3b\u673a\u4e0a\u4ee5dbadmin\u8eab\u4efd\u6267\u884cDB_CMDS\u4e2d\u7684\u547d\u4ee4\u3002<\/p>\n\n\n\n<p><strong>6.3 \u73af\u5883\u53d8\u91cf\u7684\u7ba1\u7406<\/strong><\/p>\n\n\n\n<p>sudo\u53ef\u4ee5\u63a7\u5236\u7528\u6237\u5728\u6267\u884c\u547d\u4ee4\u65f6\u7ee7\u627f\u7684\u73af\u5883\u53d8\u91cf\uff0c\u4ee5\u63d0\u9ad8\u5b89\u5168\u6027\u3002\u4f7f\u7528env_keep\u548cenv_reset\uff1a<\/p>\n\n\n\n<ul>\n<li><code>env_keep<\/code>\uff1a\u6307\u5b9a\u5141\u8bb8\u4fdd\u7559\u7684\u73af\u5883\u53d8\u91cf\u3002<\/li>\n\n\n\n<li><code>env_reset<\/code>\uff1a\u91cd\u7f6e\u73af\u5883\u53d8\u91cf\uff0c\u4ec5\u4fdd\u7559\u9ed8\u8ba4\u5141\u8bb8\u7684\u53d8\u91cf\u3002<\/li>\n<\/ul>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">Defaults env_reset\nDefaults env_keep += \"PATH LANG\"\n<\/pre>\n\n\n\n<p><strong>6.4 \u8ba1\u65f6\u6233\u548c\u8d85\u65f6\u8bbe\u7f6e<\/strong><\/p>\n\n\n\n<p>sudo\u6709\u4e00\u4e2a\u8ba1\u65f6\u6233\uff0c\u7528\u4e8e\u7ba1\u7406\u8ba4\u8bc1\u7f13\u5b58\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u7528\u6237\u5728\u4e00\u5b9a\u65f6\u95f4\u5185\u65e0\u987b\u91cd\u65b0\u8f93\u5165\u5bc6\u7801\u3002<\/p>\n\n\n\n<p>\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e<code>timestamp_timeout<\/code>\u6765\u8c03\u6574\u8d85\u65f6\u65f6\u95f4\uff08\u5355\u4f4d\uff1a\u5206\u949f\uff09\u3002<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">Defaults timestamp_timeout=10\n<\/pre>\n\n\n\n<p>\u4e0a\u8ff0\u914d\u7f6e\u5c06\u8d85\u65f6\u65f6\u95f4\u8bbe\u7f6e\u4e3a10\u5206\u949f\u3002\u8bbe\u7f6e\u4e3a<code>0<\/code>\u5c06\u6bcf\u6b21\u90fd\u8981\u6c42\u8f93\u5165\u5bc6\u7801\uff0c\u8bbe\u7f6e\u4e3a<code>-1<\/code>\u5219\u7981\u7528\u8d85\u65f6\u673a\u5236\u3002<\/p>\n\n\n\n<p><strong>6.5 \u8fd0\u884c\u522b\u540d\u7528\u6237<\/strong><\/p>\n\n\n\n<p>sudo\u5141\u8bb8\u7528\u6237\u4ee5\u4e0d\u540c\u7684\u7528\u6237\u8eab\u4efd\u8fd0\u884c\u547d\u4ee4\uff0c\u4e0d\u4ec5\u9650\u4e8eroot\u3002\u8fd9\u5bf9\u4e8e\u9700\u8981\u4ee5\u7279\u5b9a\u7528\u6237\u8eab\u4efd\u6267\u884c\u67d0\u4e9b\u4efb\u52a1\u7684\u573a\u666f\u975e\u5e38\u6709\u7528\u3002<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">sudo -u www-data \/usr\/bin\/systemctl restart nginx\n<\/pre>\n\n\n\n<p><strong>6.6 \u8fd0\u884c\u522b\u540d\u7ec4<\/strong><\/p>\n\n\n\n<p>\u9664\u5355\u4e2a\u7528\u6237\u5916\uff0c\u8fd8\u53ef\u4ee5\u8bbe\u7f6e\u7ec4\u522b\u7684\u6743\u9650\u3002<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">%webadmins ALL=(www-data) \/usr\/bin\/systemctl restart nginx\n<\/pre>\n\n\n\n<p>\u8fd9\u6837\uff0cwebadmins\u7ec4\u4e2d\u7684\u6240\u6709\u7528\u6237\u90fd\u53ef\u4ee5\u4ee5www-data\u8eab\u4efd\u91cd\u542fnginx\u670d\u52a1\u3002<\/p>\n\n\n\n<p><strong>7. \u6392\u67e5\u5e38\u89c1sudo\u95ee\u9898<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>7.1 \u6743\u9650\u4e0d\u8db3\uff1a\u6743\u9650\u88ab\u62d2\u7edd<\/strong><\/p>\n\n\n\n<p><strong>\u539f\u56e0<\/strong><\/p>\n\n\n\n<ul>\n<li>\u7528\u6237\u672a\u5728sudoers\u6587\u4ef6\u4e2d\u914d\u7f6e\u3002<\/li>\n\n\n\n<li>\u7528\u6237\u672a\u5728\u6b63\u786e\u7684\u7528\u6237\u7ec4\u4e2d\u3002<\/li>\n\n\n\n<li>sudoers\u6587\u4ef6\u914d\u7f6e\u9519\u8bef\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u89e3\u51b3\u65b9\u6cd5<\/strong><\/p>\n\n\n\n<ul>\n<li>\u786e\u8ba4\u7528\u6237\u6240\u5728\u7684\u7ec4\u662f\u5426\u8d4b\u4e88\u4e86sudo\u6743\u9650\u3002<\/li>\n\n\n\n<li>\u4f7f\u7528<code>visudo<\/code>\u68c0\u67e5sudoers\u914d\u7f6e\u662f\u5426\u6b63\u786e\u3002<\/li>\n\n\n\n<li>\u67e5\u770b\u7cfb\u7edf\u65e5\u5fd7\u4e86\u89e3\u8be6\u7ec6\u9519\u8bef\u4fe1\u606f\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>7.2 sudoers\u6587\u4ef6\u8bed\u6cd5\u9519\u8bef<\/strong><\/p>\n\n\n\n<p><strong>\u539f\u56e0<\/strong><\/p>\n\n\n\n<ul>\n<li>\u624b\u52a8\u7f16\u8f91sudoers\u6587\u4ef6\u65f6\u51fa\u73b0\u8bed\u6cd5\u9519\u8bef\u3002<\/li>\n\n\n\n<li>\u8bef\u7528\u522b\u540d\u6216\u6743\u9650\u89c4\u5219\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u89e3\u51b3\u65b9\u6cd5<\/strong><\/p>\n\n\n\n<ul>\n<li>\u59cb\u7ec8\u4f7f\u7528<code>visudo<\/code>\u7f16\u8f91sudoers\u6587\u4ef6\uff0c\u907f\u514d\u8bed\u6cd5\u9519\u8bef\u3002<\/li>\n\n\n\n<li>\u5982\u679c\u8bed\u6cd5\u9519\u8bef\u5bfc\u81f4\u65e0\u6cd5\u4f7f\u7528sudo\uff0c\u53ef\u4ee5\u4f7f\u7528root\u7528\u6237\u6216\u901a\u8fc7\u5355\u7528\u6237\u6a21\u5f0f\u4fee\u590dsudoers\u6587\u4ef6\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>7.3 \u7801\u7f13\u5b58\u95ee\u9898<\/strong><\/p>\n\n\n\n<p>\u6709\u65f6\uff0c\u7528\u6237\u53ef\u80fd\u4f1a\u53d1\u73b0sudo\u4e0d\u518d\u8981\u6c42\u8f93\u5165\u5bc6\u7801\uff0c\u6216\u603b\u662f\u8981\u6c42\u8f93\u5165\u5bc6\u7801\u3002<\/p>\n\n\n\n<p><strong>\u89e3\u51b3\u65b9\u6cd5<\/strong><\/p>\n\n\n\n<ul>\n<li>\u68c0\u67e5sudoers\u6587\u4ef6\u4e2d\u7684NOPASSWD\u9009\u9879\u3002<\/li>\n\n\n\n<li>\u68c0\u67e5<code>timestamp_timeout<\/code>\u8bbe\u7f6e\u3002<\/li>\n\n\n\n<li>\u786e\u8ba4\u7528\u6237\u7684\u8ba4\u8bc1\u7f13\u5b58\u6b63\u5e38\u5de5\u4f5c\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>7.4 \u7528\u6237\u65e0\u6cd5\u8fd0\u884c\u6307\u5b9a\u547d\u4ee4<\/strong><\/p>\n\n\n\n<p><strong>\u539f\u56e0<\/strong><\/p>\n\n\n\n<ul>\n<li>sudoers\u6587\u4ef6\u4e2d\u672a\u6b63\u786e\u914d\u7f6e\u5141\u8bb8\u7528\u6237\u6267\u884c\u7684\u547d\u4ee4\u3002<\/li>\n\n\n\n<li>\u547d\u4ee4\u7684\u8def\u5f84\u4e0d\u6b63\u786e\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>\u89e3\u51b3\u65b9\u6cd5<\/strong><\/p>\n\n\n\n<ul>\n<li>\u786e\u8ba4sudoers\u4e2d\u547d\u4ee4\u7684\u7edd\u5bf9\u8def\u5f84\u662f\u5426\u6b63\u786e\u3002<\/li>\n\n\n\n<li>\u4f7f\u7528\u522b\u540d\u6216\u901a\u914d\u7b26\u6b63\u786e\u914d\u7f6e\u547d\u4ee4\u6743\u9650\u3002<\/li>\n<\/ul>\n\n\n\n<p><strong>8. sudo\u7684\u66ff\u4ee3\u65b9\u6848<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>\u867d\u7136sudo\u529f\u80fd\u5f3a\u5927\uff0c\u4f46\u5728\u67d0\u4e9b\u573a\u666f\u4e0b\uff0c\u53ef\u80fd\u9700\u8981\u5176\u4ed6\u5de5\u5177\u4f5c\u4e3a\u66ff\u4ee3\u6216\u8865\u5145\u3002<\/p>\n\n\n\n<p><strong>8.1 su<\/strong><\/p>\n\n\n\n<p><code>su<\/code>\uff08switch user\uff09\u5141\u8bb8\u7528\u6237\u5207\u6362\u5230\u53e6\u4e00\u4e2a\u7528\u6237\u8eab\u4efd\uff0c\u9ed8\u8ba4\u5207\u6362\u5230root\u3002\u7136\u800c\uff0csu\u9700\u8981\u77e5\u9053\u76ee\u6807\u7528\u6237\u7684\u5bc6\u7801\uff0c\u4e0d\u5982<code>sudo<\/code>\u7075\u6d3b\u548c\u5b89\u5168\u3002<\/p>\n\n\n\n<p><strong>8.2 doas<\/strong><\/p>\n\n\n\n<p><code>doas<\/code>\u662fOpenBSD\u5f00\u53d1\u7684\u4e00\u4e2a\u8f7b\u91cf\u7ea7\u7684\u6743\u9650\u63d0\u5347\u5de5\u5177\uff0c\u8bed\u6cd5\u7b80\u6d01\uff0c\u914d\u7f6e\u7b80\u5355\u3002\u8fd1\u5e74\u6765\u5728Linux\u793e\u533a\u4e5f\u9010\u6e10\u53d7\u5230\u5173\u6ce8\uff0c\u88ab\u8ba4\u4e3a\u662f<code>sudo<\/code>\u7684\u4e00\u4e2a\u7b80\u6d01\u66ff\u4ee3\u65b9\u6848\u3002<\/p>\n\n\n\n<p><strong>\u5b89\u88c5doas<\/strong><\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\"># \u5728Debian\/Ubuntu\u4e0a\nsudo apt install opendoas\n\n# \u5728Arch Linux\u4e0a\nsudo pacman -S opendoas\n<\/pre>\n\n\n\n<p><strong>\u914d\u7f6edoas<\/strong><\/p>\n\n\n\n<p>\u914d\u7f6e\u6587\u4ef6\u901a\u5e38\u4f4d\u4e8e<code>\/etc\/doas.conf<\/code>\uff0c\u793a\u4f8b\u914d\u7f6e\uff1a<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">permit :wheel\npermit john as root cmd \/usr\/bin\/systemctl\n<\/pre>\n\n\n\n<p><strong>8.3 Polkit<\/strong><\/p>\n\n\n\n<p>Polkit\uff08PolicyKit\uff09\u662f\u4e00\u4e2a\u7528\u4e8e\u5b9a\u4e49\u975e\u7279\u6743\u8fdb\u7a0b\u4e0e\u7279\u6743\u8fdb\u7a0b\u4e4b\u95f4\u4ea4\u4e92\u7684\u6846\u67b6\uff0c\u5e38\u7528\u4e8e\u684c\u9762\u73af\u5883\u4e2d\u6743\u9650\u7ba1\u7406\uff0c\u4e0e<code>sudo<\/code>\u4e0d\u540c\uff0c\u66f4\u591a\u7528\u4e8e\u7cfb\u7edf\u670d\u52a1\u7684\u6743\u9650\u63a7\u5236\u3002<\/p>\n\n\n\n<p><strong>8.4 pkexec<\/strong><\/p>\n\n\n\n<p><code>pkexec<\/code>\u662fPolkit\u7684\u4e00\u90e8\u5206\uff0c\u5141\u8bb8\u7528\u6237\u4ee5\u53e6\u4e00\u4e2a\u7528\u6237\u8eab\u4efd\uff08\u901a\u5e38\u662froot\uff09\u6267\u884c\u547d\u4ee4\u3002\u4e0e<code>sudo<\/code>\u7c7b\u4f3c\uff0c\u4f46\u4f9d\u8d56\u4e8ePolkit\u8fdb\u884c\u6743\u9650\u7ba1\u7406\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u8f6c\u8f7d\uff1aLinux\u7684sudo\u6307\u4ee4\uff0c\u80cc\u540e\u505a\u4e86\u4ec0\u4e48\uff1f \u5728\u5b9e\u9645\u5de5\u4f5c\u4e2d\uff0c\u6211\u4eec\u7ecf\u5e38\u4f7f\u7528 Linux\u7684sudo\u6307\u4ee4\u8fdb\u884c\u64cd\u4f5c\u3002 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"_links":{"self":[{"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/posts\/16945"}],"collection":[{"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/92it.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16945"}],"version-history":[{"count":1,"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/posts\/16945\/revisions"}],"predecessor-version":[{"id":16946,"href":"https:\/\/92it.top\/index.php?rest_route=\/wp\/v2\/posts\/16945\/revisions\/16946"}],"wp:attachment":[{"href":"https:\/\/92it.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/92it.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/92it.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}