doas
doas (“do as”) is a program to execute commands as another user. The system administrator can configure it to give specified users privileges to execute specified commands. It is free and open-source under the ISC license[2] and available in Unix and Unix-like operating systems.
| Original author(s) | Ted Unangst |
|---|---|
| Developer(s) | OpenBSD Projects[1] |
| Initial release | 18 October 2015[1] |
| Repository | |
| Written in | C |
| Type | Security software |
| License | ISC license |
| Website | https://man.openbsd.org/doas |
doas was developed by Ted Unangst for OpenBSD as a simpler and safer sudo replacement.[3][4]
History
doas was originally developed by Ted Unangst[5] and was released with OpenBSD 5.8 in October 2015 replacing sudo.[1] However, OpenBSD still provides sudo as a package.[1]
Configuration
Definition of privileges should be written in the configuration file, /etc/doas.conf.[6]
Examples
Allow user1 to execute procmap as root without password:
permit nopass user1 as root cmd /usr/sbin/procmap
Allow members of the wheel group to run any command as root:
permit :wheel as root
Simpler version (only works if default user is root (after install it is)):
permit :wheel
To allow members of wheel group to run any command (default as root) AND remember that they entered the password:
permit persist :wheel
Ports and availability
Jesse Smith’s[7] port of doas is packaged for DragonFlyBSD,[8] FreeBSD,[9] and NetBSD.[10] According to the author, it also works on illumos and macOS.[11] OpenDoas, a Linux port, is packaged for Debian, Alpine, Arch, CRUX, Gentoo, GNU Guix, Hyperboloa, Manjaro, Parabola, NixOS, Ubuntu, and Void Linux.[12]
References
- "OpenBSD 5.8". www.openbsd.org. Archived from the original on 2021-05-17. Retrieved 2020-05-06.
- "Archived copy". Archived from the original on 2021-03-03. Retrieved 2021-09-29.CS1 maint: archived copy as title (link)
- Yegulalp, Serdar (2016-07-25). "OpenBSD 6.0 tightens security by losing Linux compatibility". InfoWorld. Archived from the original on 2021-07-25. Retrieved 2020-05-06.
- Millman, Rene (18 October 2019). "Linux Sudo bug could allow hackers root access". SC Media UK. SC Media UK. Archived from the original on 2021-09-29. Retrieved 2020-05-06.
- – OpenBSD General Commands Manual
- "Privileges | OpenBSD Handbook". www.openbsdhandbook.com. Archived from the original on 2021-03-03. Retrieved 2020-05-06.
- "Archived copy". Archived from the original on 2021-08-31. Retrieved 2020-05-06.CS1 maint: archived copy as title (link)
- "Archived copy". Archived from the original on 2021-03-03. Retrieved 2020-08-24.CS1 maint: archived copy as title (link)
- "Archived copy". Archived from the original on 2021-09-29. Retrieved 2020-08-24.CS1 maint: archived copy as title (link)
- "The NetBSD Packages Collection: security/doas". ftp.netbsd.org. Archived from the original on 2021-09-29. Retrieved 2020-05-06.
- Smith, Jesse. "doas". GitHub. Archived from the original on 2021-04-27. Retrieved 2020-08-24.
- "opendoas". repology.org. Archived from the original on 2021-03-03. Retrieved 2020-08-24.