Back to bug 1300663

Who When What Removed Added
Jakub Hrozek 2016-01-22 15:32:31 UTC Assignee sssd-maint pbrezina
Jakub Hrozek 2016-01-22 15:32:50 UTC Priority unspecified medium
Severity unspecified medium
Jakub Hrozek 2016-02-28 11:55:06 UTC Summary Improve sudo protocol Improve sudo protocol to support configurations with default_domain_suffix
Arpit Tolani 2016-03-04 10:27:25 UTC CC atolani
Arya Rajendran 2016-03-14 07:10:08 UTC CC arajendr
Fabian Zoske 2016-04-07 10:38:57 UTC CC f.zoske
Jakub Hrozek 2016-05-11 09:17:02 UTC CC jstephen
Kamil Jakubiak 2016-05-12 11:44:34 UTC CC kamil.jakubiak
John Skeoch 2016-06-01 01:28:17 UTC CC preichl
Kaleem 2016-07-04 07:28:53 UTC CC ksiddiqu
Jakub Hrozek 2016-07-07 10:47:50 UTC Status NEW POST
Jakub Hrozek 2016-07-08 11:44:58 UTC Status POST MODIFIED
Fixed In Version sssd-1.14.0-1.el7
errata-xmlrpc 2016-07-08 12:22:58 UTC Status MODIFIED ON_QA
Luc de Louw 2016-07-22 08:13:36 UTC CC ldelouw
Alex Glotov 2016-08-09 14:56:35 UTC CC aglotov
Yann Lopez 2016-09-05 13:03:37 UTC CC yann.lopez
Xiyang Dong 2016-09-21 13:04:29 UTC CC xdong
Flags needinfo?(pbrezina)
Pavel Březina 2016-09-22 07:15:45 UTC Flags needinfo?(pbrezina)
Xiyang Dong 2016-09-22 14:19:35 UTC Status ON_QA VERIFIED
Aneta Šteflová Petrová 2016-10-05 10:29:29 UTC Docs Contact apetrova
Flags needinfo?(pbrezina)
Prasad Kulkarni 2016-10-06 09:16:12 UTC Blocks 1382285
Pavel Březina 2016-10-06 10:06:01 UTC Doc Text Cause: SSSD returned correct rules to sudo but sudo did not evaluate them correctly when default_domain_suffix was set or when fully qualified name was provided.

Consequence: Sudo rule was not working.

Fix: SSSD modifies sudo rule in a way that allows sudo to evaluate it correctly.

Result: Sudo rule works.
Flags needinfo?(pbrezina)
Aneta Šteflová Petrová 2016-10-12 11:28:21 UTC Doc Text Cause: SSSD returned correct rules to sudo but sudo did not evaluate them correctly when default_domain_suffix was set or when fully qualified name was provided.

Consequence: Sudo rule was not working.

Fix: SSSD modifies sudo rule in a way that allows sudo to evaluate it correctly.

Result: Sudo rule works.
*sudo* rules now work correctly when `default_domain_suffix` is set or when including a fully-qualified name

Previously, the *sudo* utility did not correctly evaluate a *sudo* rule in these situations:

* When the `default_domain_suffix` option was used in the `/etc/sssd/sssd.conf` file
* When the *sudo* rule used a fully-qualified user name

As a consequence, the *sudo* rule did not work. With this update, the System Security Services Daemon (SSSD) modifies *sudo* rules so that *sudo* evaluates them correctly in the described situation.
Flags needinfo?(pbrezina)
Pavel Březina 2016-10-12 12:50:39 UTC Flags needinfo?(pbrezina)
Stefan Meyer 2016-10-21 11:17:12 UTC CC smeyer
errata-xmlrpc 2016-11-02 14:21:27 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2016-11-04 07:15:11 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2016-11-04 03:15:11 UTC
Pavel Březina 2020-05-02 18:17:03 UTC Link ID Github SSSD/sssd/issues/3960

Back to bug 1300663