From owner-freebsd-questions@FreeBSD.ORG Sun Aug 1 17:46:02 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 753D5106564A for ; Sun, 1 Aug 2010 17:46:02 +0000 (UTC) (envelope-from freebsd-questions-local@be-well.ilk.org) Received: from mail5.sea5.speakeasy.net (mail5.sea5.speakeasy.net [69.17.117.49]) by mx1.freebsd.org (Postfix) with ESMTP id 4C7D18FC12 for ; Sun, 1 Aug 2010 17:45:58 +0000 (UTC) Received: (qmail 28693 invoked from network); 1 Aug 2010 17:45:57 -0000 Received: from dsl092-078-145.bos1.dsl.speakeasy.net (HELO be-well.ilk.org) ([66.92.78.145]) (envelope-sender ) by mail5.sea5.speakeasy.net (qmail-ldap-1.03) with SMTP for ; 1 Aug 2010 17:45:57 -0000 Received: from lowell-desk.lan (lowell-desk.lan [172.30.250.6]) by be-well.ilk.org (Postfix) with ESMTP id A3AC050829; Sun, 1 Aug 2010 13:45:50 -0400 (EDT) Received: by lowell-desk.lan (Postfix, from userid 1147) id D5A231CC7E; Sun, 1 Aug 2010 13:45:49 -0400 (EDT) From: Lowell Gilbert To: me References: Date: Sun, 01 Aug 2010 13:45:49 -0400 In-Reply-To: (me's message of "Sat, 31 Jul 2010 02:11:16 +0530") Message-ID: <44aap6ns4y.fsf@lowell-desk.lan> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.2 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: freebsd-questions@freebsd.org Subject: Re: sudo -K/-k ineffective X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 01 Aug 2010 17:46:02 -0000 me writes: > Hi, > > Upon doing sudo as a normal user (non-root), sudo asks for > password only once, subsequent invocations of sudo doesn't ask for password > - even though I do sudo -k or sudo -K in between. > Although sudo starts asking for password after the time stamp expiry. > > in other words: > > % sudo mkdir /newdir > successful authentication> > > % sudo -k > > % sudo -K > > % sudo mkdir /another_new_dir > > > In sudoers file, NOPASSWD is NOT set. > here is my sudeors file: http://pastebin.com/WFnXCLE1 > > Output of "uname -a": > FreeBSD foo.bar 8.1-RELEASE FreeBSD 8.1-RELEASE #0: Mon Jul 19 02:55:53 UTC > 2010 > root@almeida.cse.buffalo.edu:/usr/obj/usr/src/sys/GENERIC i386 > > Is this known bug? If not, then it might have security implications. It certainly might, for anyone using the -[kK] options. However, I can't reproduce it. Works as advertised when I try your example. The only settings in my sudoers file are "timestamp_timeout=90,insults,!tty_tickets,!env_reset" (for my own account only). And your sudoers file seems to be factory standard. I don't think sudo even knows about pam(3), so I'm not sure what could be happening here...