Ubuntu 22.04中sudo执行命令时无需输入密码的异常问题求助
Ubuntu 22.04中sudo执行命令时无需输入密码的异常问题求助
各位大佬,最近碰到个诡异的问题:在我的Ubuntu 22.04系统里,每次用sudo执行命令,居然都不用输密码了!这明显不太正常啊,我自己排查了好几个地方,但还是没找到根源,来这儿求助大家帮忙看看!
我已经做的排查
检查/etc/sudoers.d目录
- 这个目录里只有一个README文件,没有其他自定义配置:
README的内容如下:myuser@MYPC:/etc/sudoers.d# ls READMEAs of Debian version 1.7.2p1-1, the default /etc/sudoers file created oninstallation of the package now includes the directive:#includedir /etc/sudoers.dThis will cause sudo to read and parse any files in the /etc/sudoers.ddirectory that do not end in '~' or contain a '.' character.Note that there must be at least one file in the sudoers.d directory (thisone will do), and all files in this directory should be mode 0440.Note also, that because sudoers contents can vary widely, no attempt ismade to add this directive to existing sudoers files on upgrade. Feel freeto add the above directive to the end of your /etc/sudoers file to enablethis functionality for existing installations if you wish!Finally, please note that using the visudo command is the recommended wayto update sudoers content, since it protects against many failure modes.See the man page for visudo for more information.
检查/etc/sudoers文件
- 仔细查看了这个核心配置文件,里面完全没有
NOPASSWD相关的配置项,文件内容如下:# # This file MUST be edited with the 'visudo' command as root. # # Please consider adding local content in /etc/sudoers.d/ instead of # directly modifying this file. # # See the man page for details on how to write a sudoers file. # Defaults env_reset Defaults mail_badpass Defaults secure_path="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin" Defaults use_pty # This preserves proxy settings from user environments of root # equivalent users (group sudo) #Defaults:%sudo env_keep += "http_proxy https_proxy ftp_proxy all_proxy no_proxy" # This allows running arbitrary commands, but so does ALL, and it means # different sudoers have their choice of editor respected. #Defaults:%sudo env_keep += "EDITOR" # Completely harmless preservation of a user preference. #Defaults:%sudo env_keep += "GREP_COLOR" # While you shouldn't normally run git as root, you need to with etckeeper #Defaults:%sudo env_keep += "GIT_AUTHOR_* GIT_COMMITTER_*" # Per-user preferences; root won't have sensible values for them. #Defaults:%sudo env_keep += "EMAIL DEBEMAIL DEBFULLNAME" # "sudo scp" or "sudo rsync" should be able to use your SSH agent. #Defaults:%sudo env_keep += "SSH_AGENT_PID SSH_AUTH_SOCK" # Ditto for GPG agent #Defaults:%sudo env_keep += "GPG_AGENT_INFO" # Host alias specification # User alias specification # Cmnd alias specification # User privilege specification root ALL=(ALL:ALL) ALL # Members of the admin group may gain root privileges #%admin ALL=(ALL) ALL # Allow members of group sudo to execute any command %sudo ALL=(ALL:ALL) ALL # See sudoers(5) for more information on "@include" directives: @includedir /etc/sudoers.d
检查用户组信息
- 我试过把自己的用户只留在sudo组里,但问题依然存在。目前我的用户组详情是:
uid=1000(myuser) gid=1000(myuser) groups=1000(myuser),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),104(input),118(lpadmin),128(sambashare),133(libvirt),138(ubridge),143(render),997(docker)
执行sudo -l查看权限
- 根据建议执行了
sudo -l命令,输出结果如下:myuser@MYPC:~$ sudo -l Matching Defaults entries for myuser on MYPC: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty User myuser may run the following commands on MYPC: (ALL : ALL) ALL
真心希望大家能帮我找到问题所在,谢谢啦!
备注:内容来源于stack exchange,提问作者Andrea Turbiglio
相关产品推荐
相关产品推荐

