Skip to content

Sudoers should disable FQDN lookups #193

@lool

Description

@lool

The default sudoers config in Debian will do FQDN lookups by default. This operation may block/timeout if the DNS/network is misconfigured.

This is quite common in typical usage scenarios, so we should disable this config by default. This is how Apertis does it:
https://gitlab.apertis.org/infrastructure/apertis-image-recipes/-/blob/apertis/v2026pre/overlays/sudo-fqdn/etc/sudoers.d/disable-fqdn?ref_type=heads

Metadata

Metadata

Assignees

Labels

debos-recipesRelates to debos recipesuserspaceRelates to Debian userspace

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions