Root, sudo & su
Linux was built to be shared by many people at once, so it cares a lot about who is allowed to do what. At the top of the pyramid sits one all-powerful account: root.
You will learn
- What root is, and why you shouldn't log in as root
- How
sudogives you superpowers one command at a time - The admin group:
wheelon Rocky,sudoon Ubuntu - Root shells:
sudo -i,suandsu -, and why root is locked - How to add a user on each family, and the classic sudo trap
- Who else is on this server?
whoandw
Meet root
root is the superuser. It can read any file, delete anything, and change any setting, with no “are you sure?” questions. Its prompt ends in # instead of $. Its home folder is /root, which is not the same as /, the root of the filesystem. Yes, the naming is confusing.
Using root all the time is like driving with no seatbelt: one typo and the whole system is gone. So instead, you use…
sudo: borrow the superpowers
sudo means “superuser do.” Put it in front of a single command to run just that command as root:
whoami # student sudo whoami # root (for this one command only) ls /root # Permission denied sudo ls /root # works
- It asks for your own password, not root's.
- After that it remembers you for a few minutes, so you don't have to retype it for every command.
- Every sudo command gets logged. Admins can see who did what.
A root shell: sudo -i, su and su -
Sometimes you have ten admin commands in a row, and typing sudo every time gets old. You can open a whole shell as root. The prompt changes to # to warn you. Type exit the moment you're done.
sudo -i # root shell, asks for YOUR password. The modern way. sudo su - # the same thing, the old-school way exit # back to being you su - # "switch user" to root. Asks for ROOT'S password. su - alex # become alex (needs alex's password, or use sudo su - alex)
The dash matters. su - gives you a full login as that user: their home folder, their settings and their PATH. Plain su switches user but keeps your current folder and environment, which can make commands mysteriously “not found.” Always use the dash.
sudo passwd -S root
root LK 2025-09-27 0 99999 7 -1 (Password locked.)
The installer asks whether to give root a password or lock it. Locking it is the recommended choice, and it's how this server is set up. Then su - fails and admins use sudo.
sudo passwd -S root
root L 2025-09-27 0 99999 7 -1
Ubuntu always locks root. su - gives “Authentication failure” no matter what you type. That's by design: use sudo -i.
Why lock root? With sudo, every admin uses their own password, every command is logged with their name, and you can take away one person's access without changing a shared root password. It also means an attacker can't guess their way into an account called “root”, a name every Linux server has.
Who's allowed to sudo? The admin group
Not everyone can use sudo, only members of a special admin group. Each family gives that group a different name:
id
uid=1000(student) gid=1000(student) groups=1000(student),10(wheel)
The admin group is wheel. The name comes from old computer slang: a “big wheel” was an important person.
id
uid=1000(student) gid=1000(student) groups=1000(student),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),100(users)
The admin group is simply called sudo. The first user made during install also gets a few extras, like adm (read logs).
Adding a user
Say a classmate named Alex needs an account on your server with admin rights:
sudo useradd alex sudo passwd alex sudo usermod -aG wheel alex
useradd creates the account and a home folder, but no password, so you set one with passwd. On Rocky, adduser is just another name for useradd.
sudo adduser alex sudo usermod -aG sudo alex
adduser is friendly and interactive: it asks for a password and details. (Ubuntu's useradd is a low-level version that doesn't create a home folder unless you add -m.)
(Lesson 13 covers managing users in depth.) usermod -aG GROUP USER means append the user to a Group. Forget the -a and you'll remove Alex from every other group! Alex has to log out and back in for the change to take effect.
The first time you use sudo on Rocky, it prints “the lecture”: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. Ubuntu skips it. It's good advice either way.
The classic sudo trap
This looks like it should work, but it doesn't:
sudo echo "hello" > /root/test.txt
bash: /root/test.txt: Permission denied
Why? The > is handled by your shell, which isn't root, before sudo even starts. sudo only powers up echo, not the arrow. The fix is tee, a command that writes whatever it receives into a file. Run tee with sudo, and feed it text using a pipe |:
echo "hello" | sudo tee /root/test.txt
The pipe | sends the output of one command into the next. It's one of the most powerful ideas in Linux. For example, history | grep cd shows only the history lines that contain “cd.”
Who else is here? who and w
A server is shared, so before you restart something it's polite (and smart) to check who's logged in:
who # who is logged in, and from where w # the same, plus what each person is running right now last # the login history (more in the processes lesson)
10:04:11 up 1:12, 1 user, load average: 0.08, 0.03, 0.01 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT student pts/0 192.168.1.23 09:51 0.00s 0.04s 0.00s w
pts/0 means a remote (SSH) session. If you see a user or an address you don't recognize, that's worth investigating. Linux Sysadmin, lesson 6 shows how.
Try it
Quick check
1. When sudo asks for a password, whose password is it?
✓ Your own. That's the point: you never need to know root's password.
2. To give user alex admin rights on Rocky, which group do you add them to?
✓ sudo usermod -aG wheel alex. On Ubuntu it would be the sudo group.
3. On Ubuntu, su - always says “Authentication failure.” How do you get a root shell?
✓ Root is locked on purpose. sudo is the front door.
4. Why does sudo echo hi > /etc/motd fail?
✓ Nice. Even experienced admins get caught by this one.