From: Donald Sharp Date: Thu, 4 May 2017 16:06:11 +0000 (-0400) Subject: *: Move sudoers file into tools X-Git-Tag: reindent-master-before~193^2~9 X-Git-Url: https://git.puffer.fish/?a=commitdiff_plain;h=2db86748db868905d222d18d3e056ebb3088281d;p=matthieu%2Ffrr.git *: Move sudoers file into tools Signed-off-by: Donald Sharp --- diff --git a/cumulus/etc/sudoers.d/frr_sudoers b/cumulus/etc/sudoers.d/frr_sudoers deleted file mode 100644 index 4a42fb24f4..0000000000 --- a/cumulus/etc/sudoers.d/frr_sudoers +++ /dev/null @@ -1,15 +0,0 @@ -Defaults env_keep += VTYSH_PAGER - -# Allow user in group frr to run vtysh show commands -# without a password by uncommenting the "%frr" line below. - -# Subshell commands need to be disallowed, including -# preventing the user passing command line args like 'start-shell' -# Since vtysh allows minimum non-conflicting prefix'es, that means -# anything beginning with the string "st" in any arg. That's a bit -# restrictive. -# Instead, use NOEXEC, to prevent any exec'ed commands. - -Cmnd_Alias VTY_SHOW = /usr/bin/vtysh -c show * -# %frr ALL = (root) NOPASSWD:NOEXEC: VTY_SHOW - diff --git a/tools/etc/sudoers.d/frr_sudoers b/tools/etc/sudoers.d/frr_sudoers new file mode 100644 index 0000000000..4a42fb24f4 --- /dev/null +++ b/tools/etc/sudoers.d/frr_sudoers @@ -0,0 +1,15 @@ +Defaults env_keep += VTYSH_PAGER + +# Allow user in group frr to run vtysh show commands +# without a password by uncommenting the "%frr" line below. + +# Subshell commands need to be disallowed, including +# preventing the user passing command line args like 'start-shell' +# Since vtysh allows minimum non-conflicting prefix'es, that means +# anything beginning with the string "st" in any arg. That's a bit +# restrictive. +# Instead, use NOEXEC, to prevent any exec'ed commands. + +Cmnd_Alias VTY_SHOW = /usr/bin/vtysh -c show * +# %frr ALL = (root) NOPASSWD:NOEXEC: VTY_SHOW +