Information
sudo (and sudo-rs, the memory-safe Rust re-implementation that is the default on Debian 13 and Ubuntu 26.04+) allows a permitted user to execute a command as the superuser or another user, as specified by the security policy. The invoking user's real (not effective) user ID is used to determine the user name with which to query the security policy.
The default security policy is sudoers, which is configured via the file /etc/sudoers and any entries in /etc/sudoers.d.
The security policy determines what privileges, if any, a user has to run sudo . The policy may require that users authenticate themselves with a password or another authentication mechanism. If authentication is required, sudo will exit if the user's password is not entered within a configurable time limit. This limit is policy-specific.
Note: sudo-rs implements a curated subset of the classic sudo Defaults flags and does not provide a plugin architecture. See https://manpages.debian.org/trixie/sudo-rs/sudo-rs.8.en.htmlfor details.
sudo supports a plug-in architecture for security policies and input/output logging. Third parties can develop and distribute their own policy and I/O logging plug-ins to work seamlessly with the sudo front end. The default security policy is sudoers, which is configured via the file /etc/sudoers and any entries in /etc/sudoers.d.
The security policy determines what privileges, if any, a user has to run sudo . The policy may require that users authenticate themselves with a password or another authentication mechanism. If authentication is required, sudo will exit if the user's password is not entered within a configurable time limit. This limit is policy-specific.
Solution
Install the appropriate sudo implementation for your environment.
Preferred on Debian 13 / Ubuntu 26.04+ (sudo-rs is the default):
# apt install sudo-rs
Classic sudo (if explicitly required for plugin support or non-standard Defaults flags):
# apt install sudo
Only if LDAP-backed sudoers via SSSD is required:
# apt install libsss-sudo sssd
Note: sudo-ldap is deprecated and being phased out. Debian 13 ("trixie") is the last Debian release to ship it; on Ubuntu 26.04 and later it is removed entirely and is not installable. For LDAP-backed sudoers on either distribution, use libsss-sudo together with sssd . The Debian sudo team recommends migrating existing sudo-ldap installations to libsss-sudo and sssd . See /usr/share/doc/sudo-ldap/NEWS.Debian.gz and Debian BTS #1033728 for more detail.