sudo su [-] <list of users>

Posted on 2010-09-04
Last Modified: 2013-12-16
I want a good syntax for allowing one group of users to be able to access a list of functional accounts using sudo.  I wrote something like

User_Alias ADMIN = a, b, c
ADMIN  ALL = (ALL) /bin/su - functional1, /bin/su - functional2, ...

I want something more elegant with '-' after su to be optional
Question by:farzanj
  • 3

Accepted Solution

apresence earned 125 total points
ID: 33605598
Hate to break the bad news, but I don't believe it is possible to do this because the sudoers file uses glob wildcards, not regular expressions.  Globs allow you to do things with allowing one or more of a certain character, etc, but do not allow you to provide alternate strings as options.  Unfortunately, if it supported regular expressions, then this would be trivial to do.

More info here:

Alternatively, you could write a script that expands a list of users into the required syntax and updates the sudoers file

Assisted Solution

apresence earned 125 total points
ID: 33605619
Another (possibly more elegant) way to do this is allow the users to run a script using sudo.  Save the attached code into /bin/su-wrap and chmod it to 700.

Your sudoers file then becomes just this:
User_Alias ADMIN = a, b, c
ADMIN ALL = (ALL) /bin/su-wrap

In my case, I'm using foo1 and foo2 as "ADMIN" users, and allowing either of them to switch to the other.  You can change the 2nd lline of the su-wrap script to list whatever users you want your admins to be able to su over to.  Using your example, you'd put:
ALLOWED_USERS="functional1 functional2".

foo1@npx1600734:~ $ sudo su-wrap - foo2
Executing: /bin/su - foo2
foo2@npx1600734:~ $ exit
foo1@npx1600734:~ $ sudo su-wrap foo2
Executing: /bin/su foo2
foo2@npx1600734:~ $

ALLOWED_USERS="foo1 foo2"


if [ "$1" = "-" ]; then




if [ $# -ne 1 ]; then

  echo "Usage: su-wrap [-] username" >&2

  exit 1


for i in $ALLOWED_USERS; do

  if [ $1 = $i ]; then

    if [ $USING_ENV -eq 1 ]; then

      CMD="/bin/su - $i"


      CMD="/bin/su $i"


    echo "Executing: $CMD"





Open in new window


Assisted Solution

apresence earned 125 total points
ID: 33605623
Two follow-up notes:
1. Make sure the /bin/su-wrap script is owned by root:root.
2. Remove the trailing "." from this line:
ALLOWED_USERS="functional1 functional2".
so it becomes:
ALLOWED_USERS="functional1 functional2"

Hope it works!
LVL 31

Author Closing Comment

ID: 33605994
I think you are right.  Kindly explain one more time why something like

/bin/su [ -] user   (notice a space)
/bin/su ? user

doesn't work.  In the first one I tried to give an option between a space and -.  In the second, I tried to use any character, hoping it would allow either a space or a hyphen.  May be I am thinking too much like regular expressions.

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
linux copy files from usb to folder on system 14 59
App holding yum lock unable to update my rpm package 1 35
php ssh2_scp_send 1 48
VMware Workstation 12 Player 16 36
Little introduction about CP: CP is a command on linux that use to copy files and folder from one location to another location. Example usage of CP as follow: cp /myfoder /pathto/destination/folder/ cp abc.tar.gz /pathto/destination/folder/ab…
Linux users are sometimes dumbfounded by the severe lack of documentation on a topic. Sometimes, the documentation is copious, but other times, you end up with some obscure "it varies depending on your distribution" over and over when searching for …
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now