Re: Issue with apt command after setting log_subcmd option in /etc/sudoers file

<[email protected]> Tue, 28 Mar 2023 15:01:47 +0000
Newsgroups gmane.comp.tools.sudo.user
Message-ID <23848_1680015707_6423015B_23848_292_1_bc98c313ea044db384d7b581d0ac5d4f@orange.com>
Hello Todd,
Thank you for your reply and the associated highlights.
It's now very clear for me.

We will see to deploy the latest package based on your package repository.

Have a good day.

Regards.

Ronan BERTIN-HUGAULT
Responsable du d=E9partement =AB=A0Z=E9ro Trust Security =BB
Digital Cloud Services
Orange/INNOV/IT-S/DCS/ZTS

[email protected]
Mobile=A0: +33 643253217


Orange Restricted

-----Message d'origine-----
De=A0: Todd C. Miller <[email protected]> =

Envoy=E9=A0: mardi 28 mars 2023 16:59
=C0=A0: BERTIN HUGAULT Ronan INNOV/IT-S <[email protected]>
Cc=A0: [email protected]
Objet=A0: Re: [sudo-users] Issue with apt command after setting log_subcmd =
option in /etc/sudoers file

On Tue, 28 Mar 2023 05:46:43 -0000, [email protected] wrote:

> On the other lines of the sudoers file regarding the Defaults item =

> there is a  space each time:
> Defaults        env_reset
> Defaults        mail_badpass
> Defaults        secure_path=3D"/usr/local/sbin:/usr/local/bin:/usr/sbin:/=
usr/bi
> n:/sbin:/bin:/snap/bin"
> Defaults        use_pty
> #Defaults       log_host, log_year
> Defaults        log_input, log_output, log_subcmds
> Defaults!/usr/bin/apt !log_subcmds
>
> If you can provide me highlight on the way sudo behave with or without =

> a spac e, I will be very interested.

There are five types of Defaults settings:

    Defaults		- global default values
    Defaults@host	- host-specific default values
    Defaults:user	- user-specific default values
    Defaults!command	- command-specific default values
    Defaults>runuser	- runas-specific default values

The host, user, command or runuser can also be a list.  Space is allowed be=
fore the host/user/command but not between "Defaults" and the special chara=
cter ('@', ':', '!' or '>').  This isn't really clear from the sudoers manu=
al--I'll try to rectify that.

> Regarding the sudo version, here are the detailed information:
> sudo --version
> Sudo version 1.9.9
> Sudoers policy plugin version 1.9.9
> Sudoers file grammar version 48
> Sudoers I/O plugin version 1.9.9
> Sudoers audit plugin version 1.9.9

That appears to be the latest version from Ubuntu.  I build my own sudo pac=
kages for common systems, including the Ubuntu LTS releases.
These are available from https://www.sudo.ws/getting/packages/.

 - todd

___________________________________________________________________________=
______________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confiden=
tielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu=
 ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages el=
ectroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou =
falsifie. Merci.

This message and its attachments may contain confidential or privileged inf=
ormation that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and dele=
te this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been =
modified, changed or falsified.
Thank you.

____________________________________________________________
sudo-users mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-users