OS/Linux

sudo ๊ถŒํ•œ ๋ถ€์—ฌ

uuuhhh 2023. 1. 28. 18:31
๐Ÿ’ก sudo : ์ผ๋ฐ˜ ์‚ฌ์šฉ์ž๊ฐ€ ์ผ์‹œ์ ์œผ๋กœ root ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์„ ์–ป๋Š” ๋ช…๋ น์–ด

 

  • ์œ„ sudo ๋ช…๋ น์–ด๋ฅผ ์ผ๋ฐ˜ ์‚ฌ์šฉ์ž๊ฐ€ ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•œ ๋ฐฉ๋ฒ•
    • /etc/sudoers ํŒŒ์ผ์— ์ผ๋ฐ˜ ์‚ฌ์šฉ์ž / ๊ทธ๋ฃน์ด ๋“ฑ๋ก๋˜์–ด ์žˆ์–ด์•ผ ํ•œ๋‹ค. 

 

  • /etc/sudoers ํŒŒ์ผ์€ readonly ์†์„ฑ์„ ๊ฐ€์ง€๊ณ  ์žˆ์–ด ํŽธ์ง‘ํ•˜๊ธฐ ์œ„ํ•œ ๋‘๊ฐ€์ง€ ๋ฐฉ๋ฒ•
    • sudoers ํŒŒ์ผ ๊ด€๋ฆฌ application ์‚ฌ์šฉ ์ถ”์ฒœ (๋ฌธ๋ฒ• ๋ฐ ์ ํ•ฉ์„ฑ ๊ฒ€์‚ฌ๋„ ํ•ด์คŒ !)
      • visudo -f /etc/sudoers
    • ํŽธ์ง‘ ๊ถŒํ•œ ๋ณ€๊ฒฝ ๋ฐ ๋ถ€์—ฌ ์ถ”์ฒœ ์•ˆํ•จ (๊ถŒํ•œ ํšŒ์ˆ˜๋ฅผ ๊นœ๋นกํ•  ์ˆ˜ ๋„ ์žˆ๊ธฐ ๋•Œ๋ฌธ !)
      • chmod u+x /etc/sudoers
      • chmod 640 /etc/sudoers

ํŒŒ์ผ ์•ˆ์—์„œ๋„ visudo๋ฅผ ๊ถŒ์žฅ(?)ํ•œ๋‹ค๊ณ  ๋งํ•˜๋„ค์—ฌ,,

 

  • sudoers ํŒŒ์ผ ํ•˜๋‹จ์— sudo ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•  ์„ค์ •์„ ์ž‘์„ฑํ•œ๋‹ค.
  • sudo ๋ช…๋ น์–ด๋ฅผ ์ฒ˜์Œ ์‚ฌ์šฉํ•  ์‹œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ด์ค˜์•ผํ•จ
    • ์ด๋ฅผ ์ƒ๋žตํ•  ์ˆ˜ ์žˆ๋Š” ์˜ต์…˜(NOPASSWD) ์„ค์ •๊ฐ€๋Šฅ
# ํŠน์ • ์‚ฌ์šฉ์ž์—๊ฒŒ sudo ์‚ฌ์šฉ ๊ถŒํ•œ ๋ถ€์—ฌ
# username ALL=(ALL) ALL
daniel ALL=(ALL) ALL

# ๊ทธ๋ฃน์— ํฌํ•จ๋œ ๋ชจ๋“  ์‚ฌ์šฉ์ž์—๊ฒŒ sudo ์‚ฌ์šฉ ๊ถŒํ•œ ๋ถ€์—ฌ
# %groupname ALL=(ALL) ALL
%student ALL=(ALL) ALL

# ํŒจ์Šค์›Œ๋“œ ์ƒ๋žต ์„ค์ •
# username ALL=(ALL) NOPASSWD: ALL
tom ALL=(ALL) NOPASSWD: ALL
%adult ALL=(ALL) NOPASSWD: ALL

 

ref.


์ผ๋ฐ˜ ์‚ฌ์šฉ์ž์—๊ฒŒ sudo ๊ถŒํ•œ ๋ถ€์—ฌ