Concept and mechanism
The account, password, and process credentials are related but distinct objects. Locking the password with passwd -l does not necessarily prevent SSH-key authentication or terminate existing sessions. Suspension procedures should cover applicable methods and sessions. Validity and expiration policies also need to match the objective. For supplementary groups, changing the account database does not automatically rewrite every running process’s credentials. Confirm configured membership and effective identity in a new session or after a controlled service restart.
Guided application
A sudo rule limited by a script’s name is only as strong as the integrity of the file and directories in its path. If the operator can replace a script run as root, its currently reviewed text does not limit future actions. Protect ownership and writes, assess authorized arguments, and inspect resources the script loads. At handover, document who can perform each action, which identity performs it, and how it is recorded. The aim is to permit necessary operations without turning a small support task into unintended general administration.
After adding a user to aps, check a new session. For a sudo script, also review permissions on the directory that permits replacing it.
Common pitfalls
Treating password lock as complete revocation; expecting group updates in old processes; reviewing only script contents.
Related topics: Shared permissions and SELinux · Tools, arguments, and reliable scripts
Effective access depends on the session and integrity of the executed path.
Reference: sudoers(5) · EX200 based on Red Hat Enterprise Linux 10