Prevent user from accessing to "su/sudo" command

asked 2014-06-13 08:18:59 -0500

Caterpillar gravatar image

Is it possible to block access to su/sudo command for a specific user?

1 Answer

answered 2014-06-13 15:16:39 -0500

KevinA gravatar image

On Fedora (and more than likely most distributions) the default control for if someone can access sudo is based on if they are in the wheel group. With regard to su access the best solution is to not give them the root password.

To remove a user from the wheel group you can use gpasswd -d [username] wheel

Yes, remove the user from the wheel group.

florian ( 2014-06-13 21:25:33 -0500 )

It can be also done graphically in Gnome: Settings->Users->Account Type should become standard rather than administrator. It also can be done with "Users and Groups" application.

hedayat ( 2014-06-14 03:00:48 -0500 )

No one of users (even mine) in my computer is part of wheel group

Caterpillar ( 2014-06-15 10:38:26 -0500 )

Are you sure? DId you run the command id from your shell? (if you are using system-settings-users: de-activate the filter for system users and groups (under settings)). Are you using Fedora?

florian ( 2014-06-15 11:24:45 -0500 )

So, none of them should be able to use sudo.

hedayat ( 2014-06-15 11:27:18 -0500 )

Asked: 2014-06-13 08:18:59 -0500

Seen: 869 times

Last updated: Jun 13 '14