sudo version as built
As mac os ventura 13.1 1/30/23
reformatted
sudo sudo -V
Sudo version 1.9.5p2
Configure options: --with-password-timeout=0 --disable-setreuid --with-env-editor --with-pam --with-libraries=bsm
--with-noexec=no --sysconfdir=/private/etc --without-lecture --enable-static-sudoers
--with-rundir=/var/db/sudo
Sudoers policy plugin version 1.9.5p2 Sudoers file grammar version 48
Sudoers path: /etc/sudoers
Authentication methods: 'pam'
Syslog facility if syslog is being used for logging: authpriv
Syslog priority to use when user authenticates successfully: notice maybe info, unsuccessfully: alert
Length at which to wrap log file lines (0 for no wrap): 80
Lecture user the first time they run sudo
File containing the sudo lecture: /etc/sudo_lecture
Path to lecture status dir: /var/db/sudo/lectured
Require users to authenticate by default
Root may run sudo
Allow some information gathering to give useful error messages
Visudo will honor the EDITOR environment variable
Set the LOGNAME and USER environment variables
Authentication timestamp timeout: 5.0 minutes
Password prompt timeout: 0.0 minutes
Number of tries to enter a password: 3
Umask to use or 0777 to use user's: 022
Send mail if the user is not in sudoers
mail:
Path to mail program: /usr/sbin/sendmail Flags for mail program: -t Address to send mail to: root
Subject line for mail messages: *** SECURITY information for %h ***
Incorrect password message: Sorry, try again.
Path to authentication timestamp dir: /var/db/sudo/ts
Default password prompt: Password:
Default user to run commands as: root
Path to the editor for use by visudo: /usr/bin/vi
When to require a password for 'list' pseudocommand: any
When to require a password for 'verify' pseudocommand: all
File descriptors >= 3 will be closed before executing a command
Reset the environment to a default set of variables
Environment variables to check for safety:
TZ TERM LINGUAS LC_* LANGUAGE LANG COLORTERM
Environment variables to remove:
*=()*
TMPPREFIX
ZDOTDIR
READNULLCMD NULLCMD
FPATH
PS4
ENV BASH_E
GLOBIGNORE
SHELLOPTS BASHOPTS
TERMCAP TERMPATH TERMINFO_DIRS TERMINFO
DYLD_*
_RLD*
LD_*
PATH_LOCALE NLSPATH
HOSTALIASES
RES_OPTIONS
LOCALDOMAIN
CDPATH
RUBYOPT RUBYLIB
PYTHONUSERBASE PYTHONINSPECT PYTHONPATH PYTHONHOME
PERL5DB PERL5OPT PERL5LIB PERLLIB PERLIO_DEBUG
JAVA_TOOL_OPTIONS
IFS Input Field Seperator
Environment variables to preserve:
MAIL HOME VISUAL EDITOR TZ SSH_AUTH_SOCK LSCOLORS COLUMNS LINES
LC_TIME LC_NUMERIC LC_MONETARY LC_MESSAGES LC_CTYPE LC_COLLATE LC_ALL LANGUAGE LANG CHARSET
__CF_USER_TEXT_ENCODING
COLORTERM COLORFGBG
LS_COLORS BLOCKSIZE
COLORS
XAUTHORIZATION XAUTHORITY
PS2 PS1
PATH
KRB5CCNAME
HOSTNAME
DISPLAY
Locale to use while parsing sudoers: C
Compress I/O logs using zlib
Directory in which to store input/output logs: /var/log/sudo-io
File in which to store the input/output log: %{seq}
Add an entry to the utmp/utmpx file when allocating a pty
PAM service name to use: sudo PAM service name to use for login shells: sudo
Attempt to establish PAM credentials for the target user
Create a new PAM session for the command to run in
Perform PAM account validation management
Enable sudoers netgroup support
Check parent directories for writability when editing files with sudoedit
Allow commands to be run even if sudo cannot write to the audit log, log file
Execute commands by file descriptor instead of by path: digest_only
Log entries larger than this value will be split into multiple syslog messages: 960
File mode to use for the I/O log files: 0600
Type of authentication timestamp record: tty
Ignore case when matching user names, group names
Log when a command is allowed by sudoers, denied
Sudo log server timeout in seconds: 30
Enable SO_KEEPALIVE socket option on the socket connected to the logserver
Verify that the log server's certificate is valid
Set the pam remote user to the user running sudo
The format of logs to produce: sudo
Local IP address and netmask pairs:
192.168.1.31/255.255.255.0
fe80::cc80:55ff:fe78:4a6[89a]/ffff:ffff:ffff:ffff::
fe80::188a:1474:f7f0:7695/ffff:ffff:ffff:ffff::
2600:4041:4310:3c00:c26:85b2:b3e2:7197/ffff:ffff:ffff:ffff::
2600:4041:4310:3c00:18f7:d784:f58:984a/ffff:ffff:ffff:ffff::
fe80::1bea:f1ed:2c88:5e7f/ffff:ffff:ffff:ffff::
fe80::383c:7fff:fe5f:b943/ffff:ffff:ffff:ffff::
fe80::383c:7fff:fe5f:b943/ffff:ffff:ffff:ffff::
fe80::608e:4b80:9573:d99b/ffff:ffff:ffff:ffff::
fe80::7a62:a2fa:102:1f32/ffff:ffff:ffff:ffff::
fe80::82e8:5148:e607:f662/ffff:ffff:ffff:ffff::
fe80::ce81:b1c:bd2c:69e/ffff:ffff:ffff:ffff::
fe80::e4dc:329a:f3b8:4402/ffff:ffff:ffff:ffff::
fe80::f592:2508:a333:2907/ffff:ffff:ffff:ffff::
Sudoers I/O plugin version 1.9.5p2
Sudoers audit plugin version 1.9.5p2