drtechno
Posts: 261
Joined: Fri Apr 09, 2021 6:33 pm

How do you remove password-less sudo from PI installation

Wed Jun 16, 2021 5:08 pm

Hello, I'm a linux user for many years, and know that the policy of password-less sudo is a bad security policy, as it makes the machine susceptible to malware.

So, How do I get the standard security that I know that is the correct way to run linux on something?

trejan
Posts: 3364
Joined: Tue Jul 02, 2019 2:28 pm

Re: How do you remove password-less sudo from PI installation

Wed Jun 16, 2021 5:14 pm

Delete /etc/sudoers.d/010_pi-nopasswd

User avatar
DougieLawson
Posts: 41470
Joined: Sun Jun 16, 2013 11:19 pm
Location: A small cave in deepest darkest Basingstoke, UK
Contact: Website Twitter

Re: How do you remove password-less sudo from PI installation

Wed Jun 16, 2021 6:24 pm

trejan wrote:
Wed Jun 16, 2021 5:14 pm
Delete /etc/sudoers.d/010_pi-nopasswd
That will leave you with no user that can run sudo.

Change the contents of 010_pi-nopasswd to

Code: Select all

pi ALL=(ALL) PASSWD: ALL
Any language using left-hand whitespace for syntax is ridiculous

Any DMs sent on Twitter will be answered next month.
Fake doctors - are all on my foes list.

Any requirement to use a crystal ball or mind reading will result in me ignoring your question.

User avatar
pasman1
Posts: 203
Joined: Mon Aug 10, 2020 3:01 pm
Location: Poland

Re: How do you remove password-less sudo from PI installation

Wed Jun 16, 2021 6:31 pm

DougieLawson wrote:
Wed Jun 16, 2021 6:24 pm
trejan wrote:
Wed Jun 16, 2021 5:14 pm
Delete /etc/sudoers.d/010_pi-nopasswd
That will leave you with no user that can run sudo.
you are wrong. look at /etc/sudoers
Pi4 RaspbOS 64+LXQT, linux 5.10.52-v8

bjtheone
Posts: 1427
Joined: Mon May 20, 2019 11:28 pm
Location: The Frozen North (AKA Canada)

Re: How do you remove password-less sudo from PI installation

Thu Jun 17, 2021 2:45 pm

Do you want to remove just the "passwordless" part of sudo, or remove sudo? Either way you will also need to add a root password, which I suspect you already know.

User avatar
thagrol
Posts: 5275
Joined: Fri Jan 13, 2012 4:41 pm
Location: Darkest Somerset, UK
Contact: Website

Re: How do you remove password-less sudo from PI installation

Thu Jun 17, 2021 3:07 pm

bjtheone wrote:
Thu Jun 17, 2021 2:45 pm
Do you want to remove just the "passwordless" part of sudo, or remove sudo? Either way you will also need to add a root password, which I suspect you already know.
Nope. Sudo asks for the password of the user invoking it not for root's password. A root password is only needed when you have no users capable of running su or sudo.
I'm a volunteer. Take me for granted or abuse my support and I will walk away

All advice given is based on my experience. it worked for me, it may not work for you.
Need help? https://github.com/thagrol/Guides

drtechno
Posts: 261
Joined: Fri Apr 09, 2021 6:33 pm

Re: How do you remove password-less sudo from PI installation

Thu Jun 17, 2021 5:46 pm

bjtheone wrote:
Thu Jun 17, 2021 2:45 pm
Do you want to remove just the "passwordless" part of sudo, or remove sudo? Either way you will also need to add a root password, which I suspect you already know.
Just removing the security flaw: "Passwordless" So it will be just like my other Linux machines I own.

Would be nice if someone's PI image didn't have this security compromise from the beginning, but I have to deal with what I am working with.

These OS on this platform also suck in a different way because there is no grub to toggle kernel versions and OS boot.

User avatar
pasman1
Posts: 203
Joined: Mon Aug 10, 2020 3:01 pm
Location: Poland

Re: How do you remove password-less sudo from PI installation

Thu Jun 17, 2021 7:35 pm

drtechno wrote:
Thu Jun 17, 2021 5:46 pm
Would be nice if someone's PI image didn't have this security compromise from the beginning, but I have to deal with what I am working with.
try ubuntu or manjaro.
Pi4 RaspbOS 64+LXQT, linux 5.10.52-v8

KeithMck
Posts: 265
Joined: Thu Dec 31, 2020 10:58 am

Re: How do you remove password-less sudo from PI installation

Fri Jun 18, 2021 9:44 am

.....or Devuan - (Debian without systemd).

User avatar
pi-anazazi
Posts: 964
Joined: Fri Feb 13, 2015 9:22 pm
Location: EU

Re: How do you remove password-less sudo from PI installation

Mon Jun 21, 2021 8:28 am

And to add some security, require root password for sudo

https://superuser.com/questions/161593/ ... t-password

...take answer by SRDC as the solution.
Kind regards

anazazi

User avatar
Milliways
Posts: 730
Joined: Fri Apr 25, 2014 12:18 am
Location: Sydney, Australia

Re: How do you remove password-less sudo from PI installation

Tue Jun 22, 2021 2:07 am

KeithMck wrote:
Fri Jun 18, 2021 9:44 am
.....or Devuan - (Debian without systemd).
Is it called this because it is antediluvian?

Return to “Advanced users”