|
|||||||
|
|
sudoersSection: FILE FORMATS (5)Updated: 1.6.3 Index Return to Main Contents ̾Á°sudoers - ¤É¤Î¥æ¡¼¥¶¤¬²¿¤ò¼Â¹Ô¤Ç¤¤ë¤«¤Î¥ê¥¹¥È½ñ¼°sudoers ¥Õ¥¡¥¤¥ë¤Ï¡¢2 ¤Ä¤Î¥¿¥¤¥×¤Î¥¨¥ó¥È¥ê¤«¤é¹½À®¤µ¤ì¤ë¡£ (´ðËÜŪ¤Ë¤ÏÊÑ¿ô¤Ç¤¢¤ë) ¥¨¥¤¥ê¥¢¥¹¤È (郎²¿¤ò¼Â¹Ô¤Ç¤¤ë¤«¤ò»ØÄꤹ¤ë) ¥æ¡¼¥¶»ØÄê¤Ç¤¢¤ë¡£ sudoers ¤Îʸˡ¤Ï¡¢ Extended Backus-Naur Form (EBNF) (³ÈÄ¥¥Ð¥Ã¥«¥¹¡¦¥Ê¥¦¥¢µË¡) ¤òÍѤ¤¤¿¤«¤¿¤Á¤Ç°Ê²¼¤Ëµ½Ò¤¹¤ë¡£ EBNF ¤òÃΤé¤Ê¤¯¤Æ¤âÄü¤á¤Ê¤¤¤Ç¤Û¤·¤¤¡£ EBNF ¤Ï³ä¤Ë´Êñ¤À¤·¡¢°Ê²¼¤ÎÄêµÁ¤Ë¤ÏÃí¼á¤ò¤Ä¤±¤Æ¤¢¤ë¡£EBNF ¤Î´Êñ¤Ê¥¬¥¤¥ÉEBNF ¤Ï¸À¸ì¤Îʸˡ¤òµ½Ò¤¹¤ë´Êñ¤Ç¸·Ì©¤ÊÊýË¡¤Ç¤¢¤ë¡£ EBNF ¤Î³ÆÄêµÁ¤Ï¡¢À¸À®µ¬Â§¤«¤é¤Ê¤Ã¤Æ¤¤¤ë¡£
¥·¥ó¥Ü¥ë ::= ÄêµÁ | Ê̤ÎÄêµÁ 1 | Ê̤ÎÄêµÁ 2 ...³ÆÀ¸À®µ¬Â§¤Ï¾¤ÎÀ¸À®µ¬Â§¤ò»²¾È¤¹¤ë¡£ ¤³¤Î¤è¤¦¤Ë¤·¤Æ¸À¸ì¤Îʸˡ¤¬¤Ç¤¤¢¤¬¤ë¡£ EBNF ¤Ï°Ê²¼¤Î¤è¤¦¤Ê¥ª¥Ú¥ì¡¼¥¿¤ò´Þ¤à¡£ ¤³¤ì¤Ï¿¤¯¤Î¿Í¤¬Àµµ¬É½¸½¤Ç¤ªÆëÀ÷¤ß¤À¤í¤¦¡£ ¤·¤«¤·¡¢¤³¤ì¤È¤Ï°Û¤Ê¤ë°ÕÌ£¤ò»ý¤Ã¤¿¡¢ ``¥ï¥¤¥ë¥É¥«¡¼¥É'' ʸ»ú¤Èº®Æ±¤·¤Æ¤Ï¤Ê¤é¤Ê¤¤ (ÌõÃí: ¸å¼Ô¤Ï¥·¥§¥ë¤Î¥ï¥¤¥ë¥É¥«¡¼¥É¥Ñ¥¿¡¼¥ó¤Î¤³¤È¤À¤í¤¦¡£ regex(7) ¤È glob(7) ¤ò»²¾È¤Î¤³¤È)¡£
³ç¸Ì¤ò»È¤¦¤È¥·¥ó¥Ü¥ë¤ò¥°¥ë¡¼¥×¤Ë¤Þ¤È¤á¤ë¤³¤È¤¬¤Ç¤¤ë¡£ °Ê¹ß¤ÎÎã¤Ç¤Ï¡¢(¥·¥ó¥Ü¥ë̾¤Ç¤Ï¤Ê¤¤) ʸ»úÄ̤ê¤Îʸ»úÎó¤Ï ¥·¥ó¥°¥ë¥¯¥ª¡¼¥È ('') ¤ò»ÈÍѤ·¤ÆÌÀ¼¨¤¹¤ë¡£ ¥¨¥¤¥ê¥¢¥¹User_Alias, Runas_Alias, Host_Alias, Cmnd_Alias ¤È¤¤¤¦ 4 ¼ïÎà¤Î¥¨¥¤¥ê¥¢¥¹¤¬¤¢¤ë¡£
Alias ::= 'User_Alias' = User_Alias (':' User_Alias)* |
'Runas_Alias' = Runas_Alias (':' Runas_Alias)* |
'Host_Alias' = Host_Alias (':' Host_Alias)* |
'Cmnd_Alias' = Cmnd_Alias (':' Cmnd_Alias)*
User_Alias ::= NAME '=' User_List Runas_Alias ::= NAME '=' Runas_User_List Host_Alias ::= NAME '=' Host_List Cmnd_Alias ::= NAME '=' Cmnd_List NAME ::= [A-Z]([A-Z][0-9]_)*³Æ¥¨¥¤¥ê¥¢¥¹ÄêµÁ¤Ï¡¢¼¡¤Î·Á¼°¤ò¤È¤ë¡£
Alias_Type NAME = item1, item2, ...¤³¤³¤Ç Alias_Type ¤Ï¡¢User_Alias, Runas_Alias, Host_Alias, Cmnd_Alias ¤Î¤¦¤Á¤Î 1 ¤Ä¤Ç¤¢¤ë¡£ NAME ¤Ï¡¢Âçʸ»ú¡¦¿ô»ú¡¦ ¥¢¥ó¥À¡¼¥¹¥³¥¢Ê¸»ú ('_') ¤«¤é¹½À®¤µ¤ì¤ëʸ»úÎó¤Ç¤¢¤ë¡£ NAME ¤ÏÂçʸ»ú¤«¤é»Ï¤Þ¤Ã¤Æ¤¤¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£ ¥»¥ß¥³¥í¥ó (':') ¤Ç¤Ä¤Ê¤²¤ì¤Ð¡¢ Ʊ°ì¥¿¥¤¥×¤ÎÊ£¿ô¤Î¥¨¥¤¥ê¥¢¥¹ÄêµÁ¤ò 1 ¹Ô¤ËÃÖ¤¯¤³¤È¤¬¤Ç¤¤ë¡£ Îã¤òµó¤²¤ë¡£
Alias_Type NAME = item1, item2, item3 : NAME = item4, item5³¤±¤Æ¡¢Í¸ú¤Ê¥¨¥¤¥ê¥¢¥¹¥á¥ó¥Ð¤ò¹½À®¤¹¤ëÍ×ÁǤÎÄêµÁ¤òµ½Ò¤¹¤ë¡£
User_List ::= User |
User ',' User_List
User ::= '!'* username |
'!'* '#'uid |
'!'* '%'group |
'!'* '+'netgroup |
'!'* User_Alias
User_List ¤Ë¤Ï¡¢¥æ¡¼¥¶Ì¾¡¦¥æ¡¼¥¶ ID (`#' ¤òÁ°¤ËÉÕ¤±¤ë)¡¦
¥·¥¹¥Æ¥à¥°¥ë¡¼¥× (`%' ¤òÁ°¤ËÉÕ¤±¤ë) ¡¦
¥Í¥Ã¥È¥°¥ë¡¼¥× (`+' ¤òÁ°¤ËÉÕ¤±¤ë)¡¦
Ê̤Υ¨¥¤¥ê¥¢¥¹¡¢¤¬ 1 ¸Ä°Ê¾å´Þ¤Þ¤ì¤ë¡£
¥ê¥¹¥È¤Î³Æ¥¢¥¤¥Æ¥à¤ÎÁ°¤Ë¤Ï¡¢1 ¸Ä°Ê¾å¤Î `!' ¥ª¥Ú¥ì¡¼¥¿¤òÃÖ¤¤¤Æ¤â¤è¤¤¡£
´ñ¿ô¸Ä¤Î `!' ¥ª¥Ú¥ì¡¼¥¿¤Ï¥¢¥¤¥Æ¥à¤ÎÃͤò̵¸ú¤Ë¤¹¤ë¡£
¶ö¿ô¸Ä¤Î¥ª¥Ú¥ì¡¼¥¿¤Ï¡¢¸ß¤¤¤ËÁ껦¤µ¤ì¤ë¤À¤±¤Ç¤¢¤ë¡£
Runas_List ::= Runas_User |
Runas_User ',' Runas_List
Runas_User ::= '!'* username |
'!'* '#'uid |
'!'* '%'group |
'!'* +netgroup |
'!'* Runas_Alias
ƱÍͤˡ¢Runas_List ¤Ï
User_List ¤ÈƱ¤¸Í×ÁǤò»ý¤Ä¤³¤È¤¬¤Ç¤¤ë¡£
¤¿¤À¤·¡¢User_Alias ¤Ç¤Ï¤Ê¤¯
Runas_Alias ¤ò´Þ¤àÅÀ¤¬°Û¤Ê¤ë¡£
Host_List ::= Host |
Host ',' Host_List
Host ::= '!'* hostname |
'!'* ip_addr |
'!'* network(/netmask)? |
'!'* '+'netgroup |
'!'* Host_Alias
Host_List ¤Ë¤Ï¡¢¥Û¥¹¥È̾¡¦IP ¥¢¥É¥ì¥¹¡¦
¥Í¥Ã¥È¥ï¡¼¥¯Èֹ桦¥Í¥Ã¥È¥°¥ë¡¼¥× (`+' ¤òÁ°¤ËÉÕ¤±¤ë)¡¦
¤½¤Î¾¤Î¥¨¥¤¥ê¥¢¥¹¡¢¤¬ 1 ¸Ä°Ê¾å´Þ¤Þ¤ì¤ë¡£
¤³¤³¤Ç¤â¡¢¥¢¥¤¥Æ¥à¤ÎÃÍ¤Ï `!' ¥ª¥Ú¥ì¡¼¥¿¤Ë¤è¤Ã¤ÆÌµ¸ú¤Ë¤µ¤ì¤ë¡£
¥Í¥Ã¥È¥ï¡¼¥¯ÈÖ¹æ¤Ë¥Í¥Ã¥È¥Þ¥¹¥¯¤ò»ØÄꤷ¤Ê¤¤¾ì¹ç¡¢
¥Û¥¹¥È¤Î¥¤¡¼¥µ¥Í¥Ã¥È¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤Î¥Í¥Ã¥È¥Þ¥¹¥¯¤¬
¥Þ¥Ã¥Á¥ó¥°¤ÎºÝ¤Ë»È¤ï¤ì¤ë¡£
¥Í¥Ã¥È¥Þ¥¹¥¯¤Ï¡¢¥É¥Ã¥È¤Ç 4 ¤Ä¤Ë¶èÀڤä¿É½µ (Î㤨¤Ð 255.255.255.0) ¤È
CIDR ɽµ (¥Ó¥Ã¥È¤Î¿ô¡¢Î㤨¤Ð 24) ¤Î¤É¤Á¤é¤Ç»ØÄꤷ¤Æ¤â¤è¤¤¡£
¥Û¥¹¥È̾¤Ë¤Ï¡¢¥·¥§¥ë·Á¼°¤Î¥ï¥¤¥ë¥É¥«¡¼¥É
(°Ê²¼¤Î `¥ï¥¤¥ë¥É¥«¡¼¥É' ¤Î¥»¥¯¥·¥ç¥ó¤ò»²¾È) ¤ò»È¤Ã¤Æ¤â¤è¤¤¡£
¤¿¤À¤·¡¢·×»»µ¡¤Î hostname ¥³¥Þ¥ó¥É¤¬
´°Á´¤Ê¥É¥á¥¤¥ó̾ÉÕ¤¤Î¥Û¥¹¥È̾¤òÊÖ¤µ¤Ê¤¤¾ì¹ç¤Ë
¥ï¥¤¥ë¥É¥«¡¼¥É¤ò»È¤¨¤ë¤è¤¦¤Ë¤¹¤ë¤Ë¤Ï¡¢
fqdn ¥ª¥×¥·¥ç¥ó¤ò»ØÄꤹ¤ëɬÍפ¬¤¢¤ë¤À¤í¤¦¡£
Cmnd_List ::= Cmnd |
Cmnd ',' Cmnd_List
commandname ::= filename |
filename args |
filename '""'
Cmnd ::= '!'* commandname |
'!'* directory |
'!'* Cmnd_Alias
Cmnd_List ¤Ï¡¢¥³¥Þ¥ó¥É̾¡¦¥Ç¥£¥ì¥¯¥È¥ê¡¦Ê̤Υ¨¥¤¥ê¥¢¥¹¡¢¤¬
1 ¸Ä°Ê¾å´Þ¤Þ¤ì¤ë¥ê¥¹¥È¤Ç¤¢¤ë¡£
¥³¥Þ¥ó¥É̾¤Ï´°Á´¤Ê¥Õ¥¡¥¤¥ë̾¤Ç¡¢¥·¥§¥ë·Á¼°¤Î¥ï¥¤¥ë¥É¥«¡¼¥É
(°Ê²¼¤Î `¥ï¥¤¥ë¥É¥«¡¼¥É' ¥»¥¯¥·¥ç¥ó¤ò»²¾È) ¤ò»È¤¦¤³¤È¤¬¤Ç¤¤ë¡£
ñ¤Ê¤ë¥Õ¥¡¥¤¥ë̾¤Ë¤¹¤ë¤È¡¢Ë¾¤ß¤Î°ú¤¿ô¤È¤È¤â¤Ë¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£
¤·¤«¤·¡¢¤µ¤é¤Ë (¥ï¥¤¥ë¥É¥«¡¼¥É¤ò¤â´Þ¤à)
¥³¥Þ¥ó¥É¥é¥¤¥ó°ú¤¿ô¤ò»ØÄꤹ¤ë¤³¤È¤â¤Ç¤¤ë¡£
È¿ÂФˡ¢¥³¥Þ¥ó¥É¥é¥¤¥ó°ú¤¿ô¤Ê¤·¤Ç¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤µ¤»¤ë¤Ë¤Ï¡¢
"" ¤ò»ØÄꤹ¤ì¤ÐÎɤ¤¡£
¥Ç¥£¥ì¥¯¥È¥ê¤Ï `/' ¤Ç¤ª¤ï¤ë´°Á´¤Ê¥Ñ¥¹Ì¾¤Ç¤¢¤ë¡£
Cmnd_List ¤Ç¥Ç¥£¥ì¥¯¥È¥ê¤ò»ØÄꤹ¤ë¤È¡¢
¥æ¡¼¥¶¤Ï¤½¤Î¥Ç¥£¥ì¥¯¥È¥ê¤Ë¤¢¤ëÁ´¤Æ¤Î¥Õ¥¡¥¤¥ë¤ò¼Â¹Ô¤Ç¤¤ë
(¤·¤«¤·¡¢¤½¤Î¥µ¥Ö¥Ç¥£¥ì¥¯¥È¥ê¤Ë¤¢¤ë¥Õ¥¡¥¤¥ë¤Ï¼Â¹Ô¤Ç¤¤Ê¤¤)¡£
Cmnd ¤¬¥³¥Þ¥ó¥É¥é¥¤¥ó°ú¤¿ô¤È´ØÏ¢¤Å¤±¤é¤ì¤Æ¤¤¤ë¾ì¹ç¡¢ Cmnd ¤ÎÃæ¤Î°ú¤¿ô¤Ï¡¢ ¥æ¡¼¥¶¤¬¥³¥Þ¥ó¥É¥é¥¤¥ó¤Ç»ØÄꤷ¤¿°ú¤¿ô¤È´°Á´¤Ë¥Þ¥Ã¥Á¤·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤ (¥ï¥¤¥ë¥É¥«¡¼¥É¤¬¤¢¤Ã¤¿¾ì¹ç¤Ï¡¢¤½¤ì¤È´°Á´¤Ë¥Þ¥Ã¥Á¤·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤)¡£ /`,', `:', `=', `\' ¤È¤¤¤¦Ê¸»ú¤ò ¥³¥Þ¥ó¥É¥é¥¤¥ó°ú¤¿ô¤È¤·¤Æ»È¤¦¾ì¹ç¡¢ /`\' ¤Ç¥¨¥¹¥±¡¼¥×¤·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤ÅÀ¤ËÃí°Õ¤¹¤ë¤³¤È¡£ ¥Ç¥Õ¥©¥ë¥È¤¢¤ëÀßÄꥪ¥×¥·¥ç¥ó¤ÎÃͤò¡¢1 ¹Ô°Ê¾å¤Î Default_Entry ¹Ô¤ò»È¤Ã¤Æ¡¢ ¥Ç¥Õ¥©¥ë¥È¤ÎÃͤ«¤éÊѹ¹¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£ ¤³¤Î¹Ô¤¬¸ú²Ì¤ò»ý¤ÄÈϰϤϡ¢Á´¤Æ¤Î¥Û¥¹¥È¾å¤ÎÁ´¤Æ¤Î¥æ¡¼¥¶¤Ë¤¹¤ë¤³¤È¤â¡¢ »ØÄꤷ¤¿¥Û¥¹¥È¾å¤ÎÁ´¤Æ¤Î¥æ¡¼¥¶¤Ë¤¹¤ë¤³¤È¤â¡¢ »ØÄꤷ¤¿¥æ¡¼¥¶¤Ë¤¹¤ë¤³¤È¤â¤Ç¤¤ë¡£ Ê£¿ô¤Î¥¨¥ó¥È¥ê¤¬¥Þ¥Ã¥Á¤¹¤ë¾ì¹ç¤Ï¡¢½çÈÖ¤ËŬÍѤµ¤ì¤ë¡£ Ì·½â¤¹¤ëÃͤ¬¤¢¤ë¾ì¹ç¤Ï¡¢¥Þ¥Ã¥Á¤¹¤ë¹Ô¤ÎºÇ¸å¤ÎÃͤ¬¸ú²Ì¤ò»ý¤Ä¡£
Default_Type ::= 'Defaults' ||
'Defaults' ':' User ||
'Defaults' '@' Host
Default_Entry ::= Default_Type Parameter_List
Parameter ::= Parameter '=' Value ||
'!'* Parameter ||
Parameter ¤Ï ¥Õ¥é¥°¡¦À°¿ô¡¦Ê¸»úÎó ¤Î¤¤¤º¤ì¤«¤Ç¤¢¤ë¡£
¥Õ¥é¥°¤Ï¼Â¤Ï¿¿µ¶ÃͤǤ¢¤ê¡¢`!' ¥ª¥Ú¥ì¡¼¥¿¤Ç off ¤Ë¤Ç¤¤ë¡£
À°¿ô¤Èʸ»úÎó¥Ñ¥é¥á¡¼¥¿¤Î¤Ê¤«¤Ë¤â¿¿µ¶ÃͤΰÕÌ£¤Ç»È¤¨¤ë¤â¤Î¤¬¤¢¤ê¡¢
¤½¤ì¤é¤Ï̵¸ú¤Ë¤Ç¤¤ë¡£
ÃͤËÊ£¿ô¤Î¥ï¡¼¥É¤¬´Þ¤Þ¤ì¤ë¾ì¹ç¤Ï¡¢
¥À¥Ö¥ë¥¯¥ª¡¼¥È (") ¤Ç°Ï¤Þ¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£
ÆÃ¼ìʸ»ú¤Ï¥Ð¥Ã¥¯¥¹¥é¥Ã¥·¥å (\) ¤Ç¥¨¥¹¥±¡¼¥×¤·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£
¥Õ¥é¥°:
À°¿ô:
¿¿µ¶ÃͤȤ·¤Æ¤â»ÈÍѤµ¤ì¤ëÀ°¿ô:
ʸ»úÎó:
¿¿µ¶ÃͤȤ·¤Æ¤â»ÈÍѤµ¤ì¤ëʸ»úÎó:
syslog(3) ¤Ç¥í¥°¤òµÏ¿¤·¤Æ¤¤¤ë¾ì¹ç¡¢ sudo ¤Ï syslog ¤Î facility (syslog ¥Ñ¥é¥á¡¼¥¿¤ÎÃÍ) ¤È¤·¤Æ¡¢ authpriv (OS ¤¬¥µ¥Ý¡¼¥È¤·¤Æ¤¤¤ë¾ì¹ç), auth, daemon, user, local0, local1, local2, local3, local4, local5, local6, local7 ¤ò¼õ¤±ÉÕ¤±¤ë¡£ syslog ¤Î prioritiy ¤È¤·¤Æ¤Ï¡¢ alert, crit, debug, emerg, err, info, notice, warning ¤¬¥µ¥Ý¡¼¥È¤µ¤ì¤Æ¤¤¤ë¡£ ¥æ¡¼¥¶ÀßÄê
User_Spec ::= User_list Host_List '=' User_List Cmnd_Spec_List \
(':' User_Spec)*
Cmnd_Spec_List ::= Cmnd_Spec |
Cmnd_Spec ',' Cmnd_Spec_List
Cmnd_Spec ::= Runas_Spec? ('NOPASSWD:' | 'PASSWD:')? Cmnd
Runas_Spec ::= '(' Runas_List ')'
¥æ¡¼¥¶ÀßÄê¤Ï¡¢»ØÄꤷ¤¿¥Û¥¹¥È¾å¤Ç¥æ¡¼¥¶¤¬ (¤É¤Î¥æ¡¼¥¶¤È¤·¤Æ)
¤É¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¤«¤ò·èÄꤹ¤ë¡£
¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï¥³¥Þ¥ó¥É¤Ï root ¤È¤·¤Æ¼Â¹Ô¤µ¤ì¤ë¤¬¡¢
¤³¤ì¤Ï¥³¥Þ¥ó¥ÉËè¤ËÊѹ¹²Äǽ¤Ç¤¢¤ë¡£
¥æ¡¼¥¶ÀßÄê¤ò¹½À®Í×ÁǤ´¤È¤Ëʬ¤±¤Æ¤ß¤ë¡£ Runas_SpecRunas_Spec ¤Ïñ¤Ë (¾å¤ÇÄêµÁ¤·¤¿) Runas_List ¤ò³ç¸Ì¤Ç³ç¤Ã¤¿¤â¤Î¤Ç¤¢¤ë¡£ ¥æ¡¼¥¶ÀßÄê¤Ç Runas_Spec ¤ò»ØÄꤷ¤Ê¤¤¤È¡¢ root ¤Î¥Ç¥Õ¥©¥ë¥È¤Î Runas_Spec ¤¬»È¤ï¤ì¤ë¡£ Runas_Spec ¤Ï¡¢¤½¤Î¸å¤Ë³¤¯¥³¥Þ¥ó¥É¤Î¥Ç¥Õ¥©¥ë¥È¤òÀßÄꤹ¤ë¡£ ¤Ä¤Þ¤ê:
dgb boulder = (operator) /bin/ls, /bin/kill, /usr/bin/who¤Î¤è¤¦¤Ê¥¨¥ó¥È¥ê¤¬¤¢¤ë¾ì¹ç¡¢ ¥æ¡¼¥¶ dgb ¤Ï¡¢/bin/ls, /bin/kill, /usr/bin/lprm ¤ò ¼Â¹Ô¤Ç¤¤ë¡£-- ¤¿¤À¤· operator ¤È¤·¤Æ¤Î¤ß¡£Î㤨¤Ð:
sudo -u operator /bin/ls.
Runas_Spec ¤ò¸å¤«¤é¥¨¥ó¥È¥ê¤ÎÃæ¤Ç¾å½ñ¤¤¹¤ë¤³¤È¤â²Äǽ¤Ç¤¢¤ë¡£
dgb boulder = (operator) /bin/ls, (root) /bin/kill, /usr/bin/lprm¤Î¤è¤¦¤Ë½¤Àµ¤¹¤ë¤È¡¢ ¥æ¡¼¥¶ dgb ¤Ï /bin/ls ¤ò operator ¤È¤·¤Æ¡¢ ¤Þ¤¿ /bin/kill ¤È /usr/bin/lprm ¤ò root ¤È¤·¤Æ ¼Â¹Ô¤¹¤ë¤³¤È¤¬µö²Ä¤µ¤ì¤ë¡£ NOPASSWD ¤È PASSWD¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï¡¢sudo ¤Ï ¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤¹¤ëÁ°¤Ë¥æ¡¼¥¶¼«¿È¤Îǧ¾Ú¤òɬÍפȤ¹¤ë¡£ ¤³¤Îưºî¤Ï NOPASSWD ¥¿¥°¤ÇÊѹ¹¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£ Runas_Spec ¤ÈƱÍͤˡ¢NOPASSWD ¥¿¥°¤Ï ¥³¥Þ¥ó¥É¤Î¥Ç¥Õ¥©¥ë¥È¤ò¤½¤Î¸å¤Ë³¤¯ Cmnd_Spec_List ¤ËÀßÄꤹ¤ë¡£ µÕ¤Ë PASSWD ¤Ï¤³¤ì¤ò¸µ¤ËÌ᤹¤¿¤á¤Ë»È¤ï¤ì¤ë¡£ Î㤨¤Ð:
ray rushmore = NOPASSWD: /bin/kill, /bin/ls, /usr/bin/lprm¤È¤¹¤ë¤È¡¢¥æ¡¼¥¶ ray ¤ÏÈ༫¿È¤Ø¤Îǧ¾Ú¤Ê¤·¤Ç ·×»»µ¡ rushmore ¤Î root ¤È¤·¤Æ /bin/kill, /bin/ls, /usr/bin/lprm ¤ò¼Â¹Ô¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£ ray ¤Ë /bin/kill ¤À¤±¤ò ¥Ñ¥¹¥ï¡¼¥É¤Ê¤·¤Ç¼Â¹Ô¤µ¤»¤ë¤è¤¦¤Ë¤·¤¿¤¤¾ì¹ç¡¢¥¨¥ó¥È¥ê¤Ï¼¡¤Î¤è¤¦¤Ë¤Ê¤ë¡£
ray rushmore = NOPASSWD: /bin/kill, PASSWD: /bin/ls, /usr/bin/lprm¤¿¤À¤·¡¢PASSWD ¥¿¥°¤Ï exempt_group ¥ª¥×¥·¥ç¥ó¤Ç »ØÄꤵ¤ì¤¿¥°¥ë¡¼¥×¤Ë°¤·¤Æ¤¤¤ë¥æ¡¼¥¶¤Ë¤Ï¸ú²Ì¤¬¤Ê¤¤ÅÀ¤ËÃí°Õ¤¹¤ë¤³¤È¡£ ¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï¡¢¸½ºß¤Î¥Û¥¹¥È¾å¤Î¤¢¤ë¥æ¡¼¥¶¤Î¤É¤ì¤«¤Î¥¨¥ó¥È¥ê¤Ë NOPASSWD ¥¿¥°¤¬Å¬ÍѤµ¤ì¤Æ¤¤¤ì¤Ð¡¢ ¤½¤Î¥æ¡¼¥¶¤Ï sudo -l ¤ò¥Ñ¥¹¥ï¡¼¥É¤Ê¤·¤Ë¼Â¹Ô¤Ç¤¤ë¤è¤¦¤Ë¤Ê¤ë¡£ ¤µ¤é¤Ë¡¢¤¢¤ë¥æ¡¼¥¶¤Î¸½ºß¤Î¥Û¥¹¥È¤Ë´ØÏ¢¤¹¤ëÁ´¤Æ¤Î¥¨¥ó¥È¥ê¤Ë NOPASSWD ¥¿¥°¤¬¤¢¤ë¾ì¹ç¤Ë¸Â¤ê¡¢ ¤½¤Î¥æ¡¼¥¶¤Ï sudo -v ¤ò¥Ñ¥¹¥ï¡¼¥É¤Ê¤·¤Ë¼Â¹Ô¤Ç¤¤ë¤è¤¦¤Ë¤Ê¤ë¡£ ¤³¤Îưºî¤Ï verifypw ¤È listpw ¥ª¥×¥·¥ç¥ó¤ò»È¤Ã¤ÆÊѹ¹¤Ç¤¤ë¡£ ¥ï¥¤¥ë¥É¥«¡¼¥É (ÊÌ̾¡¢¥á¥¿¥¥ã¥é¥¯¥¿):sudo ¤Ï sudoers ¥Õ¥¡¥¤¥ë¤Ë¤ª¤¤¤Æ¡¢ ¥³¥Þ¥ó¥É¥é¥¤¥ó°ú¤¿ô¤ä¥Ñ¥¹Ì¾¤ËÂФ·¤Æ ¥·¥§¥ë·Á¼°¤Î¥ï¥¤¥ë¥É¥«¡¼¥É¤ò»È¤¦¤³¤È¤¬¤Ç¤¤ë¡£ ¥ï¥¤¥ë¥É¥«¡¼¥É¤Î¥Þ¥Ã¥Á¥ó¥°¤Ï¡¢ POSIX ¤Î fnmatch(3) ¥ë¡¼¥Á¥ó¤ò»È¤Ã¤Æ¹Ô¤ï¤ì¤ë¡£ Àµµ¬É½¸½¤Ç¤Ï¤Ê¤¤ÅÀ¤ËÃí°Õ¤¹¤ë¤³¤È¡£
¥Õ¥©¥ï¡¼¥É¥¹¥é¥Ã¥·¥å ('/') ¤Ï¡¢¥Ñ¥¹Ì¾¤Ç»È¤ï¤ì¤ë¥ï¥¤¥ë¥É¥«¡¼¥É¤ËÂФ·¤Æ¤Ï ¥Þ¥Ã¥Á¤·¤Ê¤¤ÅÀ¤ËÃí°Õ¤¹¤ë¤³¤È¡£ ¥³¥Þ¥ó¥É¥é¥¤¥ó°ú¤¿ô¤ËÂФ·¤Æ¥Þ¥Ã¥Á¥ó¥°¤ò¤¹¤ë¾ì¹ç¡¢ ¥¹¥é¥Ã¥·¥å¤Ï¥ï¥¤¥ë¥É¥«¡¼¥É¤Ë¥Þ¥Ã¥Á¤¹¤ë¡£ ¤³¤ì¤Ï
/usr/bin/*
¤Î¤è¤¦¤Ê¥Ñ¥¹¤ò¡¢
/usr/bin/who ¤Ë¤Ï¥Þ¥Ã¥Á¤µ¤»¡¢
/usr/bin/X11/xterm ¤Ë¤Ï¥Þ¥Ã¥Á¤µ¤»¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤¿¤á¤Ç¤¢¤ë¡£
¥ï¥¤¥ë¥É¥«¡¼¥É¤Îµ¬Â§¤Ë¤ª¤±¤ëÎã³°:¾å¤Îµ¬Â§¤ËÂФ·¤Æ¡¢¼¡¤ÎÎã³°¤¬Å¬ÍѤµ¤ì¤ë¡£
¤½¤Î¾¤ÎÆÃ¼ìʸ»ú¤ÈͽÌó¸ì:¥·¥ã¡¼¥×µ¹æ ('#') ¤Ï¥³¥á¥ó¥È¤òɽ¤¹¤¿¤á¤Ë»È¤ï¤ì¤ë¡£ (¥æ¡¼¥¶Ì¾¤Ç»È¤ï¤ì¤Æ¤¤¤ë¾ì¹ç¤Ï½ü¤¯¡£ ¤Þ¤¿¡¢1 ¸Ä°Ê¾å¤Î¿ô»ú¤¬Â³¤¤¤Æ¤¤¤Æ¡¢¥æ¡¼¥¶ ID ¤È¤·¤Æ°·¤ï¤ì¤ë¾ì¹ç¤â½ü¤¯¡£) ¥³¥á¥ó¥Èʸ»ú¤È¤½¤ì°Ê¹ß¤Î¥Æ¥¥¹¥È¤Ï¡¢¹ÔËö¤Þ¤Ç̵»ë¤µ¤ì¤ë¡£Í½Ìó¸ì ALL ¤ÏÁȹþ¤ß¤Î¥¨¥¤¥ê¥¢¥¹¤Ç¡¢ ¾ï¤Ë¥Þ¥Ã¥Á¤òÀ®¸ù¤µ¤»¤ë¡£ ¤³¤ÎͽÌó¸ì¤Ï¤É¤³¤Ç¤â»È¤¨¤ë¡£ ¤³¤ì¤ò»È¤¤¤¿¤¯¤Ê¤¤¾ì¹ç¤Ï¡¢ Cmnd_Alias, User_Alias, Runas_Alias, Host_Alias ¤ò»È¤¦¤³¤È¡£ ALL ¤È¤¤¤¦ ¥¨¥¤¥ê¥¢¥¹ ¤ò¼«Ê¬¤ÇÄêµÁ¤·¤è¤¦¤È¤·¤Æ¤Ï¤Ê¤é¤Ê¤¤¡£ Áȹþ¤ß¤Î¥¨¥¤¥ê¥¢¥¹¤¬Í¥À褵¤ì¤ë¤«¤é¤Ç¤¢¤ë¡£ ALL ¤ò»È¤¦¤È´í¸±¤Ë¤Ê¤ë²ÄǽÀ¤¬¤¢¤ëÅÀ¤ËÃí°Õ¤¹¤ë¤³¤È¡£ ¤Ê¤¼¤Ê¤é¡¢¤³¤ì¤ò¥³¥Þ¥ó¥É¤Î»ØÄê¤Ç»È¤¦¤È¡¢ ¥æ¡¼¥¶¤Ï¥·¥¹¥Æ¥à¾å¤ÎÁ´¤Æ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¤«¤é¤Ç¤¢¤ë¡£ ´¶Ã²Éä ('!') ¤Ï¡¢¥¨¥¤¥ê¥¢¥¹¤ÎÃæ¤È Cmnd ¤ÎÁ°¤Ç¡¢ ÏÀÍý³Ø¤Î not ¥ª¥Ú¥ì¡¼¥¿¤È¤·¤Æ»È¤¦¤³¤È¤¬¤Ç¤¤ë¡£ ¤³¤ì¤Ë¤è¤ê¡¢¤¢¤ëÃͤòÇÓ½ü¤Ç¤¤ë¡£ ¤·¤«¤· ! ¤òÁȹþ¤ß¤Î ALL ¥¨¥¤¥ê¥¢¥¹¤ÈÁȤ߹ç¤ï¤»¤Æ¡¢ ¥æ¡¼¥¶¤¬ ``Á´¤Æ¤Ç¤Ï¤Ê¤¯°ìÉô¤Î'' ¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¤è¤¦¤Ë ¤·¤è¤¦¤È¤·¤Æ¤â¡¢°Õ¿Þ¤·¤¿¤è¤¦¤Ëưºî¤¹¤ë¤³¤È¤Ïµ©¤Ç¤¢¤ëÅÀ¤ËÃí°Õ¤¹¤ë¤³¤È (°Ê²¼¤Î¡Ö¥»¥¥å¥ê¥Æ¥£¾å¤ÎÃí°Õ¡×¤ò»²¾È)¡£ Ť¤¹Ô¤Ï¡¢¥Ð¥Ã¥¯¥¹¥é¥Ã¥·¥å ('\') ¤ò¹Ô¤ÎºÇ¸å¤Îʸ»ú¤Ë¤¹¤ì¤Ð ³¤±¤ë¤³¤È¤¬¤Ç¤¤ë¡£ ¥ê¥¹¥È¤Ë¤ª¤±¤ë¹½À®Í×ÁǴ֤ζõÇò¤ä¡¢ ¥æ¡¼¥¶ÀßÄê¤Ë¤ª¤±¤ëÆÃ¼ì¤Ê¹½Ê¸Ê¸»ú ('=', `:', `(', `)') ¤Ï¡¢¤Ê¤¯¤Æ¤â¤è¤¤¡£ '@', `!', `=', `:', `,', `(', `)', `\' ¤È¤¤¤¦Ê¸»ú¤ò¥ï¡¼¥É (Î㤨¤Ð¡¢¥æ¡¼¥¶Ì¾¤ä¥Û¥¹¥È̾) ¤Î°ìÉô¤È¤·¤Æ»È¤¦¾ì¹ç¤Ï¡¢ ¥Ð¥Ã¥¯¥¹¥é¥Ã¥·¥å ('\') ¤Ç¥¨¥¹¥±¡¼¥×¤·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£ Îã°Ê²¼¤Ï sudoers ¥¨¥ó¥È¥ê¤ÎÎã¤Ç¤¢¤ë¡£ ÀµÄ¾¤Ê¤È¤³¤í¡¢¤¤¤¯¤Ä¤«¤Ï¾¯¤·¤ï¤¶¤È¤é¤·¤¤¡£ »Ï¤á¤Ë¥¨¥¤¥ê¥¢¥¹¤òÄêµÁ¤¹¤ë¡£
# User alias specification User_Alias FULLTIMERS = millert, mikef, dowdy User_Alias PARTTIMERS = bostley, jwfox, crawl User_Alias WEBMASTERS = will, wendy, wim # Runas alias specification Runas_Alias OP = root, operator Runas_Alias DB = oracle, sybase
# Host alias specification
Host_Alias SPARC = bigtime, eclipse, moet, anchor :\
SGI = grolsch, dandelion, black :\
ALPHA = widget, thalamus, foobar :\
HPPA = boa, nag, python
Host_Alias CUNETS = 128.138.0.0/255.255.0.0
Host_Alias CSNETS = 128.138.243.0, 128.138.204.0/24, 128.138.242.0
Host_Alias SERVERS = master, mail, www, ns
Host_Alias CDROM = orion, perseus, hercules
# Cmnd alias specification
Cmnd_Alias DUMPS = /usr/bin/mt, /usr/sbin/dump, /usr/sbin/rdump,\
/usr/sbin/restore, /usr/sbin/rrestore
Cmnd_Alias KILL = /usr/bin/kill
Cmnd_Alias PRINTING = /usr/sbin/lpc, /usr/bin/lprm
Cmnd_Alias SHUTDOWN = /usr/sbin/shutdown
Cmnd_Alias HALT = /usr/sbin/halt, /usr/sbin/fasthalt
Cmnd_Alias REBOOT = /usr/sbin/reboot, /usr/sbin/fastboot
Cmnd_Alias SHELLS = /usr/bin/sh, /usr/bin/csh, /usr/bin/ksh, \
/usr/local/bin/tcsh, /usr/bin/rsh, \
/usr/local/bin/zsh
Cmnd_Alias SU = /usr/bin/su
°Ê²¼¤ÎÀßÄê¤Ç¤Ï¡¢¥³¥ó¥Ñ¥¤¥ë»þ¤Î¥Ç¥Õ¥©¥ë¥ÈÃͤΤ¤¤¯¤Ä¤«¤ò¾å½ñ¤¤¹¤ë¡£
sudo ¤Ë syslog(3) ¤ò»È¤Ã¤Æ
Á´¤Æ¤Î¾ì¹ç¤Ë¤Ä¤¤¤Æ auth facility ¤Ç¥í¥°¤òµÏ¿¤µ¤»¤ë¡£
¥Õ¥ë¥¿¥¤¥à¤Î¥¹¥¿¥Ã¥Õ¤Ë¤Ï¡¢sudo ¤Î¥ì¥¯¥Á¥ã¡¼¤ò¼õ¤±¤ëɬÍפò¤Ê¤¯¤¹¡£
¤Þ¤¿¥æ¡¼¥¶ millert ¤Ï¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Ê¤¯¤Æ¤è¤¤¤è¤¦¤Ë¤¹¤ë¡£
¤µ¤é¤Ë Host_Alias ¤Î SERVERS ¤Ë¤¢¤ë·×»»µ¡¤Ë
(syslog ¤È¤ÏÊ̤Ë) ¥í¡¼¥«¥ë¤Î¥í¥°¥Õ¥¡¥¤¥ë¤òÊݸ¤·¡¢
Ť¤¥í¥°¥¨¥ó¥È¥ê¤ò¿ôǯ¤ËÅϤêÊݸ¤¹¤ë¤¿¤á¤Ë¥í¥°¤Î³Æ¹Ô¤Ëǯ¤òµÏ¿¤¹¤ë¡£
# Override builtin defaults Defaults syslog=auth Defaults:FULLTIMERS !lecture Defaults:millert !authenticate Defaults@SERVERS log_year, logfile=/var/log/sudo.log¥æ¡¼¥¶ÀßÄê¤Ï¡¢Ã¯¤¬²¿¤ò¼Â¹Ô¤Ç¤¤ë¤«¤ò¼ÂºÝ¤Ë·èÄꤷ¤Æ¤¤¤ëÉôʬ¤Ç¤¢¤ë¡£
root ALL = (ALL) ALL %wheel ALL = (ALL) ALLroot ¤È wheel ¥°¥ë¡¼¥×¤Î¥æ¡¼¥¶¤Ë¡¢ Á´¤Æ¤Î¥æ¡¼¥¶¤È¤·¤Æ¡¢Á´¤Æ¤Î¥Û¥¹¥È¾å¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¤è¤¦¤Ë¤·¤Æ¤¤¤ë¡£
FULLTIMERS ALL = NOPASSWD: ALL¥Õ¥ë¥¿¥¤¥à¤Î¥·¥¹¥Æ¥à´ÉÍý¼Ô (millert, mikef, dowdy) ¤Ï¡¢ ¼«Ê¬¼«¿È¤Îǧ¾Ú¤ò¤¹¤ë¤³¤È¤Ê¤¯¡¢Á´¤Æ¤Î¥Û¥¹¥È¾å¤ÇÁ´¤Æ¤Î¥³¥Þ¥ó¥É¤¬¼Â¹Ô¤Ç¤¤ë¡£
PARTTIMERS ALL = ALL¥Ñ¡¼¥È¥¿¥¤¥à¤Î¥·¥¹¥Æ¥à´ÉÍý¼Ô (bostley, jwfox, crawl) ¤Ï¡¢ Á´¤Æ¤Î¥Û¥¹¥È¾å¤ÇÁ´¤Æ¤Î¥³¥Þ¥ó¥É¤¬¼Â¹Ô¤Ç¤¤ë¤¬¡¢ (¥¨¥ó¥È¥ê¤Ë NOPASSWD ¥¿¥°¤¬¤Ê¤¤¤Î¤Ç) ºÇ½é¤Ë¼«Ê¬¼«¿È¤Îǧ¾Ú¤¬É¬ÍפǤ¢¤ë¡£
jack CSNETS = ALL¥æ¡¼¥¶ jack ¤Ï¡¢CSNETS ¥¨¥¤¥ê¥¢¥¹ (¥Í¥Ã¥È¥ï¡¼¥¯ 128.138.243.0, 128.138.204.0, 128.138.242.0) ¤Ë¤¢¤ë·×»»µ¡¾å¤Ç¡¢Á´¤Æ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¡£ ¤³¤ì¤é¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤Î¤¦¤Á¡¢¥Í¥Ã¥È¥ï¡¼¥¯ <128.138.204.0> ¤À¤±¤Ë ¥¯¥é¥¹ C ¥Í¥Ã¥È¥ï¡¼¥¯¤ò¼¨¤¹ÌÀ¼¨Åª¤Ê (CIDR ɽµ¤Î) ¥Í¥Ã¥È¥Þ¥¹¥¯¤¬¤¢¤ë¡£ CSNETS ¤Ë¤¢¤ë¾¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤Ë¤Ä¤¤¤Æ¤Ï¡¢ ¥Þ¥Ã¥Á¥ó¥°¤ÎºÝ¤Ë¥í¡¼¥«¥ë¤Î·×»»µ¡¤Î¥Í¥Ã¥È¥Þ¥¹¥¯¤¬»È¤ï¤ì¤ë¡£
lisa CUNETS = ALL¥æ¡¼¥¶ lisa ¤Ï¡¢CUNETS ¥¨¥¤¥ê¥¢¥¹ (¥¯¥é¥¹ B ¥Í¥Ã¥È¥ï¡¼¥¯ 128.138.0.0) ¤Ë¤¢¤ë Á´¤Æ¤Î¥Û¥¹¥È¤Ç¡¢Á´¤Æ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¡£
operator ALL = DUMPS, KILL, PRINTING, SHUTDOWN, HALT, REBOOT,\
/usr/oper/bin/
¥æ¡¼¥¶ operator ¤Ï¡¢
´Êñ¤Ê¥á¥ó¥Æ¥Ê¥ó¥¹ÍѤΥ³¥Þ¥ó¥É¤Ë¸Â¤Ã¤Æ¼Â¹Ô¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£
¤³¤ì¤é¤Ï¥Ç¥£¥ì¥¯¥È¥ê /usr/oper/bin/ ¤Ë¤¢¤ë¥³¥Þ¥ó¥ÉÁ´¤Æ¤Ç¡¢
¥Ð¥Ã¥¯¥¢¥Ã¥×¡¦¥×¥í¥»¥¹¤Î kill¡¦°õºþ¥·¥¹¥Æ¥à¡¦¥·¥¹¥Æ¥à¤Î¥·¥ã¥Ã¥È¥À¥¦¥ó¡¢
¤È¤¤¤Ã¤¿¤³¤È¤Ë´ØÏ¢¤·¤¿¤â¤Î¤Ç¤¢¤ë¡£
joe ALL = /usr/bin/su operator¥æ¡¼¥¶ joe ¤Ï¡¢operator ¤Ë¤Ê¤ë¤¿¤á¤Î su(1) ¤·¤«¼Â¹Ô¤Ç¤¤Ê¤¤¡£
pete HPPA = /usr/bin/passwd [A-z]*, !/usr/bin/passwd root¥æ¡¼¥¶ pete ¤Ï¡¢HPPA ·×»»µ¡¾å¤Ç root °Ê³°¤ÎÁ´¤Æ¤Î¥æ¡¼¥¶¤Î¥Ñ¥¹¥ï¡¼¥É¤òÊѹ¹¤¹¤ë¤³¤È¤¬µö²Ä¤µ¤ì¤Æ¤¤¤ë¡£ ¤³¤³¤Ç¤Ï¡¢passwd(1) ¤¬¥³¥Þ¥ó¥É¥é¥¤¥ó¤«¤é Ê£¿ô¤Î¥æ¡¼¥¶Ì¾¤ò¼õ¤±ÉÕ¤±¤Ê¤¤¤³¤È¤ò²¾Äꤷ¤Æ¤¤¤ëÅÀ¤ËÃí°Õ¤¹¤ë¤³¤È¡£
bob SPARC = (OP) ALL : SGI = (OP) ALL¥æ¡¼¥¶ bob ¤Ï¡¢SPARC ¤È SGI ·×»»µ¡¾å¤Ç¡¢ Runas_Alias ¤Î OP ¤Ë¥ê¥¹¥È¤µ¤ì¤¿¥æ¡¼¥¶ (root ¤È operator) ¤È¤·¤Æ¡¢Á´¤Æ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¡£
jim +biglab = ALL¥æ¡¼¥¶ jim ¤Ï¡¢biglab ¥Í¥Ã¥È¥°¥ë¡¼¥×¤Ë¤¢¤ëÁ´¤Æ¤Î·×»»µ¡¤Ç¡¢ Á´¤Æ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¡£ sudo ¤Ï¡¢``biglab'' ¤¬¥Í¥Ã¥È¥°¥ë¡¼¥×¤Ç¤¢¤ë¤³¤È¤ò ¥×¥ì¥Õ¥£¥Ã¥¯¥¹ `+' ¤Ë¤è¤Ã¤ÆÃΤ롣
+secretaries ALL = PRINTING, /usr/bin/adduser, /usr/bin/rmusersecretaries ¥Í¥Ã¥È¥°¥ë¡¼¥×¤Ë°¤¹¤ë¥æ¡¼¥¶¤Ï¡¢ ¥æ¡¼¥¶¤ÎÄɲᦺï½ü¤À¤±¤Ç¤Ê¤¯¥×¥ê¥ó¥¿´ÉÍý¤ÎÊä½õ¤ò¤¹¤ëɬÍפ¬¤¢¤ë¤Î¤Ç¡¢ ¤³¤ì¤é¤Î¥³¥Þ¥ó¥É¤òÁ´¤Æ¤Î·×»»µ¡¾å¤Ç¼Â¹Ô¤¹¤ë¤³¤È¤¬µö²Ä¤µ¤ì¤Æ¤¤¤ë¡£
fred ALL = (DB) NOPASSWD: ALL¥æ¡¼¥¶ fred ¤Ï¡¢Runas_Alias ¤Î DB ¤Ë¤¢¤ë¥æ¡¼¥¶ (oracle ¤È sybase) ¤È¤·¤Æ¡¢¥Ñ¥¹¥ï¡¼¥É¤Ê¤·¤Ç¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¡£
john ALPHA = /usr/bin/su [!-]*, !/usr/bin/su *root*ALPHA ·×»»µ¡¾å¤Ç¡¢¥æ¡¼¥¶ john ¤Ï¡¢ su ¤Ç root °Ê³°¤ÎÁ´¤Æ¤Î¥æ¡¼¥¶¤Ë¤Ê¤ì¤ë¡£ ¤·¤«¤· su(1) ¤Ë¥Õ¥é¥°¤ò»ØÄꤹ¤ë¤³¤È¤Ï¤Ç¤¤Ê¤¤¡£
jen ALL, !SERVERS = ALL¥æ¡¼¥¶ jen ¤Ï¡¢Host_Alias ¤Î SERVERS ¤Ë¤¢¤ë·×»»µ¡ (master, mail, www, ns) °Ê³°¤Ç¡¢Á´¤Æ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¡£
jill SERVERS = /usr/bin/, !SU, !SHELLSHost_Alias ¤Î SERVERS ¤Ë¤¢¤ë·×»»µ¡¤Ç¡¢ jill ¤Ï /usr/bin ¥Ç¥£¥ì¥¯¥È¥ê¤Ë¤¢¤ëÁ´¤Æ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¡£ ¤¿¤À¤·¡¢Cmnd_Aliases ¤Î SU ¤È SHELLS ¤Ë°¤·¤Æ¤¤¤ë¥³¥Þ¥ó¥É¤Ï½ü¤¯¡£
steve CSNETS = (operator) /usr/local/op_commands/¥æ¡¼¥¶ steve ¤Ï¡¢¥Ç¥£¥ì¥¯¥È¥ê /usr/local/op_commands/ ¤Ë¤¢¤ë Á´¤Æ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¡£¤¿¤À¤·¡¢¥æ¡¼¥¶ operator ¤È¤·¤Æ¤Î¤ß¼Â¹Ô¤Ç¤¤ë¡£
matt valkyrie = KILLmatt ¤Ï¡¢Èà¤Î¸Ä¿Í¤Î¥ï¡¼¥¯¥¹¥Æ¡¼¥·¥ç¥ó valkyrie ¤Ç¡¢ ¥Ï¥ó¥°¤·¤¿¥×¥í¥»¥¹¤ò kill ¤Ç¤¤ëɬÍפ¬¤¢¤ë¡£
WEBMASTERS www = (www) ALL, (root) /usr/bin/su www¥Û¥¹¥È www ¤Ç¡¢User_Alias ¤Î WEBMASTERS ¤Ë¤¢¤ë¥æ¡¼¥¶ (will, wendy, wim) ¤Ï¡¢(web ¥Ú¡¼¥¸¤ò½êͤ·¤Æ¤¤¤ë) ¥æ¡¼¥¶ www ¤È¤·¤Æ Á´¤Æ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤ë¡£ ¤Þ¤¿¡¢Ã±¤Ë su(1) ¤Ç www ¤Ë¤Ê¤ì¤ë& | ||||||