Pluggable Authentication Modules (PAM)
netbsd.org
netbsd.org
Edited the config with "sudo nano /etc/pam.d/sudo", a typo slipped in, saved the file and closed nano. After that sudo was broken and I had to go down the rabbit hole of changing a root owned system file without sudo to fix it.
The next time I opened a root shell with "sudo -s" and THEN opened nano. Made absolutely sure sudo still works in a new Terminal window before closing anything.
BSD Authentication is much nicer, but has only been adopted by OpenBSD.
[0] For people rolling their own NAS, mostly with SAMFS, at least one with ZFS.
To put it bluntly, my personal opinion is that it is a massive piece of shit. It makes even simple things feel complicated for no reason whatsoever and is so brittle. The whole thing is a huge design failure.
Specifically: it just skips asking at all. No extra step like pushing a button.
[0]: https://github.com/m00dy/pam-backdoor/blob/master/pam-backdo...