Re: default /etc/sudoers in Linux distributions

Simon Lees via sudo-workers <[email protected]> Mon, 2 Feb 2026 13:14:07 +1030
Newsgroups gmane.comp.tools.sudo.devel
Message-ID <[email protected]>
Hi

On 2/1/26 7:35 AM, Todd C. Miller via sudo-workers wrote:
> On Thu, 29 Jan 2026 10:47:15 +0100, Marc Haber wrote:
> 
>> The absence of an upstream default sudoers file makes consistence more
>> difficult since we didn't have a common ground to start from. the
>> example sudoers file in the upstream distribution looks to me more like
>> a feature demonstration as like something that is intended to be
>> actually used.
> 
> You are correct that the sudoers file in the examples directory
> is more intended to demonstrate various sudoers syntax.
> 
> However, there is another sudoers file, plugins/sudoers/sudoers.in
> that gets installed as part of "make install" after substitutions
> are performed.  I think that one could be used as a starting point.
> 
>   - todd

Within SUSE and openSUSE Distributions SUSE's security team is 
responsible for making decisions on what goes into our policy. Currently 
we start with the file in "plugins/sudoers/sudoers.in" and apply the 
following patch 
https://build.opensuse.org/projects/Base:System/packages/sudo/files/sudo-sudoers.patch?expand=1

We also ship sub packages that allow anyone in the sudoers and or wheel 
group access to authenticate using there own password.

-- 
Simon Lees (Simotek)                            http://simotek.net

Emergency Update Team                           keybase.io/simotek
SUSE Linux                           Adelaide Australia, UTC+10:30
GPG Fingerprint: 5B87 DB9D 88DC F606 E489 CEC5 0922 C246 02F0 014B

____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers