Linux Basics · Lesson 12 · 20 min

Root, sudo & su

Linux was built to be shared by many people at once, so it cares a lot about who is allowed to do what. At the top of the pyramid sits one all-powerful account: root.

You will learn

  • What root is, and why you shouldn't log in as root
  • How sudo gives you superpowers one command at a time
  • The admin group: wheel on Rocky, sudo on Ubuntu
  • Root shells: sudo -i, su and su -, and why root is locked
  • How to add a user on each family, and the classic sudo trap
  • Who else is on this server? who and w

Meet root

root is the superuser. It can read any file, delete anything, and change any setting, with no “are you sure?” questions. Its prompt ends in # instead of $. Its home folder is /root, which is not the same as /, the root of the filesystem. Yes, the naming is confusing.

Using root all the time is like driving with no seatbelt: one typo and the whole system is gone. So instead, you use…

sudo: borrow the superpowers

sudo means “superuser do.” Put it in front of a single command to run just that command as root:

Same on both
whoami          # student
sudo whoami     # root  (for this one command only)
ls /root        # Permission denied
sudo ls /root   # works

A root shell: sudo -i, su and su -

Sometimes you have ten admin commands in a row, and typing sudo every time gets old. You can open a whole shell as root. The prompt changes to # to warn you. Type exit the moment you're done.

Same on both
sudo -i          # root shell, asks for YOUR password. The modern way.
sudo su -        # the same thing, the old-school way
exit             # back to being you
su -             # "switch user" to root. Asks for ROOT'S password.
su - alex        # become alex (needs alex's password, or use sudo su - alex)

The dash matters. su - gives you a full login as that user: their home folder, their settings and their PATH. Plain su switches user but keeps your current folder and environment, which can make commands mysteriously “not found.” Always use the dash.

Rocky / RHEL
sudo passwd -S root
root LK 2025-09-27 0 99999 7 -1 (Password locked.)

The installer asks whether to give root a password or lock it. Locking it is the recommended choice, and it's how this server is set up. Then su - fails and admins use sudo.

Ubuntu / Debian
sudo passwd -S root
root L 2025-09-27 0 99999 7 -1

Ubuntu always locks root. su - gives “Authentication failure” no matter what you type. That's by design: use sudo -i.

Why lock root? With sudo, every admin uses their own password, every command is logged with their name, and you can take away one person's access without changing a shared root password. It also means an attacker can't guess their way into an account called “root”, a name every Linux server has.

Who's allowed to sudo? The admin group

Not everyone can use sudo, only members of a special admin group. Each family gives that group a different name:

Rocky / RHEL
id
uid=1000(student) gid=1000(student) groups=1000(student),10(wheel)

The admin group is wheel. The name comes from old computer slang: a “big wheel” was an important person.

Ubuntu / Debian
id
uid=1000(student) gid=1000(student) groups=1000(student),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),100(users)

The admin group is simply called sudo. The first user made during install also gets a few extras, like adm (read logs).

Adding a user

Say a classmate named Alex needs an account on your server with admin rights:

Rocky / RHEL
sudo useradd alex
sudo passwd alex
sudo usermod -aG wheel alex

useradd creates the account and a home folder, but no password, so you set one with passwd. On Rocky, adduser is just another name for useradd.

Ubuntu / Debian
sudo adduser alex
sudo usermod -aG sudo alex

adduser is friendly and interactive: it asks for a password and details. (Ubuntu's useradd is a low-level version that doesn't create a home folder unless you add -m.)

(Lesson 13 covers managing users in depth.) usermod -aG GROUP USER means append the user to a Group. Forget the -a and you'll remove Alex from every other group! Alex has to log out and back in for the change to take effect.

One more Rocky quirk

The first time you use sudo on Rocky, it prints “the lecture”: #1) Respect the privacy of others. #2) Think before you type. #3) With great power comes great responsibility. Ubuntu skips it. It's good advice either way.

The classic sudo trap

This looks like it should work, but it doesn't:

Same on both
sudo echo "hello" > /root/test.txt
bash: /root/test.txt: Permission denied

Why? The > is handled by your shell, which isn't root, before sudo even starts. sudo only powers up echo, not the arrow. The fix is tee, a command that writes whatever it receives into a file. Run tee with sudo, and feed it text using a pipe |:

Same on both
echo "hello" | sudo tee /root/test.txt

The pipe | sends the output of one command into the next. It's one of the most powerful ideas in Linux. For example, history | grep cd shows only the history lines that contain “cd.”

Who else is here? who and w

A server is shared, so before you restart something it's polite (and smart) to check who's logged in:

Same on both
who        # who is logged in, and from where
w          # the same, plus what each person is running right now
last       # the login history (more in the processes lesson)
 10:04:11 up 1:12,  1 user,  load average: 0.08, 0.03, 0.01
USER     TTY      FROM             LOGIN@   IDLE   JCPU   PCPU  WHAT
student  pts/0    192.168.1.23     09:51    0.00s  0.04s  0.00s w

pts/0 means a remote (SSH) session. If you see a user or an address you don't recognize, that's worth investigating. Linux Sysadmin, lesson 6 shows how.

Try it

Quick check

1. When sudo asks for a password, whose password is it?

2. To give user alex admin rights on Rocky, which group do you add them to?

3. On Ubuntu, su - always says “Authentication failure.” How do you get a root shell?

4. Why does sudo echo hi > /etc/motd fail?

Finished the missions and the quiz? Mark it done to track your progress.