file distributed with s\bsu\bud\bdo\bo or https://www.sudo.ws/license.html for
complete details.
-Sudo 1.8.26 October 6, 2018 Sudo 1.8.26
+Sudo 1.8.26 October 7, 2018 Sudo 1.8.26
file distributed with s\bsu\bud\bdo\bo or https://www.sudo.ws/license.html for
complete details.
-Sudo 1.8.25 June 16, 2018 Sudo 1.8.25
+Sudo 1.8.26 October 7, 2018 Sudo 1.8.26
.\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
.\" ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.TH "SUDO.CONF" "5" "June 16, 2018" "Sudo @PACKAGE_VERSION@" "File Formats Manual"
+.TH "SUDO.CONF" "5" "October 7, 2018" "Sudo @PACKAGE_VERSION@" "File Formats Manual"
.nh
.if n .ad l
.SH "NAME"
\fBdevname\fR()
or
\fB_ttyname_dev\fR()
-functions, for example BSD, macOS and Solaris.
+functions, for example
+BSD,
+macOS and Solaris.
.TP 10n
noexec
The fully-qualified path to a shared library containing wrappers
To actually get a
\fBsudo\fR
core file you will likely need to enable core dumps for setuid processes.
-On BSD and Linux systems this is accomplished in the
+On
+BSD
+and Linux systems this is accomplished in the
sysctl(@mansectsu@)
command.
On Solaris, the
such queries.
Currently,
\fBsudo\fR
-supports efficient group queries on AIX, BSD, HP-UX, Linux and
-Solaris.
+supports efficient group queries on AIX,
+BSD,
+HP-UX, Linux and Solaris.
.TP 10n
adaptive
Only query the group database if the static group list returned
.\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
.\" ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.Dd June 16, 2018
+.Dd October 7, 2018
.Dt SUDO.CONF @mansectform@
.Os Sudo @PACKAGE_VERSION@
.Sh NAME
.Fn devname
or
.Fn _ttyname_dev
-functions, for example BSD, macOS and Solaris.
+functions, for example
+.Bx ,
+macOS and Solaris.
.It noexec
The fully-qualified path to a shared library containing wrappers
for the
To actually get a
.Nm sudo
core file you will likely need to enable core dumps for setuid processes.
-On BSD and Linux systems this is accomplished in the
+On
+.Bx
+and Linux systems this is accomplished in the
.Xr sysctl 8
command.
On Solaris, the
such queries.
Currently,
.Nm sudo
-supports efficient group queries on AIX, BSD, HP-UX, Linux and
-Solaris.
+supports efficient group queries on AIX,
+.Bx ,
+HP-UX, Linux and Solaris.
.It adaptive
Only query the group database if the static group list returned
by the kernel has the maximum number of entries.
.\" Agency (DARPA) and Air Force Research Laboratory, Air Force
.\" Materiel Command, USAF, under agreement number F39502-99-1-0512.
.\"
-.TH "SUDO" "8" "October 6, 2018" "Sudo @PACKAGE_VERSION@" "System Manager's Manual"
+.TH "SUDO" "8" "October 7, 2018" "Sudo @PACKAGE_VERSION@" "System Manager's Manual"
.nh
.if n .ad l
.SH "NAME"
.RE
.TP 12n
\fB\-a\fR \fItype\fR, \fB\--auth-type\fR=\fItype\fR
-Use the specified BSD authentication
+Use the specified
+BSD
+authentication
\fItype\fR
when validating the user, if allowed by
\fI/etc/login.conf\fR.
\(lqauth-sudo\(rq
entry in
\fI/etc/login.conf\fR.
-This option is only available on systems that support BSD authentication.
+This option is only available on systems that support
+BSD
+authentication.
.TP 12n
\fB\-b\fR, \fB\--background\fR
Run the given command in the background.
\fI/etc/login.conf\fR
settings, such as the umask and environment variables, will
be applied, if present.
-This option is only available on systems with BSD login classes.
+This option is only available on systems with
+BSD
+login classes.
.TP 12n
\fB\-E\fR, \fB\--preserve-env\fR
Indicates to the security policy that the user wishes to
.\" Agency (DARPA) and Air Force Research Laboratory, Air Force
.\" Materiel Command, USAF, under agreement number F39502-99-1-0512.
.\"
-.Dd October 6, 2018
+.Dd October 7, 2018
.Dt SUDO @mansectsu@
.Os Sudo @PACKAGE_VERSION@
.Sh NAME
.Nm
will exit with an error.
.It Fl a Ar type , Fl -auth-type Ns = Ns Ar type
-Use the specified BSD authentication
+Use the specified
+.Bx
+authentication
.Ar type
when validating the user, if allowed by
.Pa /etc/login.conf .
.Dq auth-sudo
entry in
.Pa /etc/login.conf .
-This option is only available on systems that support BSD authentication.
+This option is only available on systems that support
+.Bx
+authentication.
.It Fl b , -background
Run the given command in the background.
Note that it is not possible to use shell job control to manipulate
.Pa /etc/login.conf
settings, such as the umask and environment variables, will
be applied, if present.
-This option is only available on systems with BSD login classes.
+This option is only available on systems with
+.Bx
+login classes.
.It Fl E , -preserve-env
Indicates to the security policy that the user wishes to
preserve their existing environment variables.
.It
Solaris privileges
.It
-BSD login class
+.Bx No login class
.It
scheduling priority (aka nice value)
.El
Authentication type, if specified by the
\fB\-a\fR
flag, to use on
-systems where BSD authentication is supported.
+systems where
+BSD
+authentication is supported.
.PD
.TP 6n
closefrom=number
will pass the plugin the path to the user's shell and set
.TP 6n
login_class=string
-BSD login class to use when setting resource limits and nice value,
+BSD
+login class to use when setting resource limits and nice value,
if specified by the
\fB\-c\fR
flag.
This is a hint to the I/O logging plugin which may choose to ignore it.
.TP 6n
login_class=string
-BSD login class to use when setting resource limits and nice value
-(optional).
+BSD
+login class to use when setting resource limits and nice value (optional).
This option is only set on systems that support login classes.
.TP 6n
nice=int
Nice value (priority) to use when executing the command.
The nice value, if specified, overrides the priority associated with the
\fIlogin_class\fR
-on BSD systems.
+on
+BSD
+systems.
.TP 6n
noexec=bool
If set, prevent the command from executing other programs.
Authentication type, if specified by the
.Fl a
flag, to use on
-systems where BSD authentication is supported.
+systems where
+.Bx
+authentication is supported.
.It closefrom=number
If specified, the user has requested via the
.Fl C
.Nm sudo
will pass the plugin the path to the user's shell and set
.It login_class=string
-BSD login class to use when setting resource limits and nice value,
+.Bx
+login class to use when setting resource limits and nice value,
if specified by the
.Fl c
flag.
This only includes output to the screen, not output to a pipe or file.
This is a hint to the I/O logging plugin which may choose to ignore it.
.It login_class=string
-BSD login class to use when setting resource limits and nice value
-(optional).
+.Bx
+login class to use when setting resource limits and nice value (optional).
This option is only set on systems that support login classes.
.It nice=int
Nice value (priority) to use when executing the command.
The nice value, if specified, overrides the priority associated with the
.Em login_class
-on BSD systems.
+on
+.Bx
+systems.
.It noexec=bool
If set, prevent the command from executing other programs.
.It preserve_fds=list
file distributed with s\bsu\bud\bdo\bo or https://www.sudo.ws/license.html for
complete details.
-Sudo 1.8.26 October 6, 2018 Sudo 1.8.26
+Sudo 1.8.26 October 7, 2018 Sudo 1.8.26
file distributed with s\bsu\bud\bdo\bo or https://www.sudo.ws/license.html for
complete details.
-Sudo 1.8.26 September 27, 2018 Sudo 1.8.26
+Sudo 1.8.26 October 7, 2018 Sudo 1.8.26
.\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
.\" ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.TH "SUDOERS.LDAP" "5" "September 27, 2018" "Sudo @PACKAGE_VERSION@" "File Formats Manual"
+.TH "SUDOERS.LDAP" "5" "October 7, 2018" "Sudo @PACKAGE_VERSION@" "File Formats Manual"
.nh
.if n .ad l
.SH "NAME"
.\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
.\" ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.Dd September 27, 2018
+.Dd October 7, 2018
.Dt SUDOERS.LDAP @mansectform@
.Os Sudo @PACKAGE_VERSION@
.Sh NAME
The server certificate will be requested.
A missing certificate is ignored but an invalid certificate will
result in a connection error.
-.It demand No | Ar hard
+.It demand | Ar hard
The server certificate will be requested.
A missing or invalid certificate will result in a connection error.
This is the default behavior.
.\" Agency (DARPA) and Air Force Research Laboratory, Air Force
.\" Materiel Command, USAF, under agreement number F39502-99-1-0512.
.\"
-.TH "SUDOERS" "5" "October 6, 2018" "Sudo @PACKAGE_VERSION@" "File Formats Manual"
+.TH "SUDOERS" "5" "October 7, 2018" "Sudo @PACKAGE_VERSION@" "File Formats Manual"
.nh
.if n .ad l
.SH "NAME"
contents of the
\fI/etc/environment\fR
file.
-On BSD systems, if the
+On
+BSD
+systems, if the
\fIuse_loginclass\fR
option is enabled, the environment is initialized
based on the
\fI/etc/environment\fR
are also
included.
-On BSD systems, if the
+On
+BSD
+systems, if the
\fIuse_loginclass\fR
flag is
enabled, the
written.
This flag is only effective on systems for which
\fBsudoers\fR
-supports audit logging, including FreeBSD, Linux, macOS and Solaris.
+supports audit logging, including
+FreeBSD,
+Linux, macOS and Solaris.
This flag is
\fIon\fR
by default.
By default,
\fBsudoers\fR
creates log messages up to 980 bytes which corresponds to the
-historic BSD syslog implementation which used a 1024 byte buffer
+historic
+BSD
+syslog implementation which used a 1024 byte buffer
to store the message, date, hostname and program name.
To prevent syslog messages from being truncated,
\fBsudoers\fR
\fItimestamp_timeout\fR
values are not supported and positive values are limited to a maximum
of 60 minutes.
-This is currently only supported on OpenBSD.
+This is currently only supported on
+OpenBSD.
.PP
The default value is
\fI@timestamp_type@\fR.
.\" Agency (DARPA) and Air Force Research Laboratory, Air Force
.\" Materiel Command, USAF, under agreement number F39502-99-1-0512.
.\"
-.Dd October 6, 2018
+.Dd October 7, 2018
.Dt SUDOERS @mansectform@
.Os Sudo @PACKAGE_VERSION@
.Sh NAME
contents of the
.Pa /etc/environment
file.
-On BSD systems, if the
+On
+.Bx
+systems, if the
.Em use_loginclass
option is enabled, the environment is initialized
based on the
.Pa /etc/environment
are also
included.
-On BSD systems, if the
+On
+.Bx
+systems, if the
.Em use_loginclass
flag is
enabled, the
written.
This flag is only effective on systems for which
.Nm
-supports audit logging, including FreeBSD, Linux, macOS and Solaris.
+supports audit logging, including
+.Fx ,
+Linux, macOS and Solaris.
This flag is
.Em on
by default.
By default,
.Nm
creates log messages up to 980 bytes which corresponds to the
-historic BSD syslog implementation which used a 1024 byte buffer
+historic
+.Bx
+syslog implementation which used a 1024 byte buffer
to store the message, date, hostname and program name.
To prevent syslog messages from being truncated,
.Nm
.Em timestamp_timeout
values are not supported and positive values are limited to a maximum
of 60 minutes.
-This is currently only supported on OpenBSD.
+This is currently only supported on
+.Ox .
.El
.Pp
The default value is
file distributed with s\bsu\bud\bdo\bo or https://www.sudo.ws/license.html for
complete details.
-Sudo 1.8.26 October 6, 2018 Sudo 1.8.26
+Sudo 1.8.26 October 7, 2018 Sudo 1.8.26
.\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
.\" ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.TH "SUDOERS_TIMESTAMP" "5" "October 6, 2018" "Sudo @PACKAGE_VERSION@" "File Formats Manual"
+.TH "SUDOERS_TIMESTAMP" "5" "October 7, 2018" "Sudo @PACKAGE_VERSION@" "File Formats Manual"
.nh
.if n .ad l
.SH "NAME"
This prevents re-use of the time stamp file after logout in most cases.
.sp
Support was added for the kernel-based tty time stamps available in
-OpenBSD which do not use an on-disk time stamp file.
+OpenBSD
+which do not use an on-disk time stamp file.
.SH "AUTHORS"
Many people have worked on
\fBsudo\fR
.\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
.\" ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.Dd October 6, 2018
+.Dd October 7, 2018
.Dt SUDOERS_TIMESTAMP @mansectform@
.Os Sudo @PACKAGE_VERSION@
.Sh NAME
This prevents re-use of the time stamp file after logout in most cases.
.Pp
Support was added for the kernel-based tty time stamps available in
-OpenBSD which do not use an on-disk time stamp file.
+.Ox
+which do not use an on-disk time stamp file.
.El
.Sh AUTHORS
Many people have worked on