← RHCSA: RHEL 10 production administration
07 / 8 · 25 MIN

Identities, sessions, and delegation

Review effective access and delegated-command integrity.

Concept and mechanism

The account, password, and process credentials are related but distinct objects. Locking the password with passwd -l does not necessarily prevent SSH-key authentication or terminate existing sessions. Suspension procedures should cover applicable methods and sessions. Validity and expiration policies also need to match the objective. For supplementary groups, changing the account database does not automatically rewrite every running process’s credentials. Confirm configured membership and effective identity in a new session or after a controlled service restart.

Guided application

A sudo rule limited by a script’s name is only as strong as the integrity of the file and directories in its path. If the operator can replace a script run as root, its currently reviewed text does not limit future actions. Protect ownership and writes, assess authorized arguments, and inspect resources the script loads. At handover, document who can perform each action, which identity performs it, and how it is recorded. The aim is to permit necessary operations without turning a small support task into unintended general administration.

IN PRACTICE

After adding a user to aps, check a new session. For a sudo script, also review permissions on the directory that permits replacing it.

Common pitfalls

Treating password lock as complete revocation; expecting group updates in old processes; reviewing only script contents.

Related topics: Shared permissions and SELinux · Tools, arguments, and reliable scripts

Take this idea with you

Effective access depends on the session and integrity of the executed path.

Create account

Reference: sudoers(5) · EX200 based on Red Hat Enterprise Linux 10