Back to bug 759480

Who When What Removed Added
RHEL Program Management 2011-12-02 14:10:23 UTC Keywords Rebase
Peter Vrabec 2011-12-06 08:27:00 UTC CC pvrabec
Daniel Kopeček 2011-12-06 08:46:03 UTC Priority unspecified urgent
Severity unspecified medium
Jakub Hrozek 2011-12-08 16:15:37 UTC Blocks 761573
Daniel Kopeček 2012-01-03 11:40:08 UTC Status NEW ASSIGNED
Eduard Benes 2012-01-09 12:24:17 UTC CC ebenes
Aleš Mareček 2012-02-01 10:43:36 UTC CC amarecek
Flags needinfo?(dkopecek)
Severity medium high
Dmitri Pal 2012-02-01 17:55:06 UTC CC dpal, jhrozek, sgallagh
Daniel Kopeček 2012-02-02 12:29:31 UTC Flags needinfo?(dkopecek)
Karel Srot 2012-02-07 13:54:34 UTC CC ksrot
Flags needinfo?(jhrozek) needinfo?(dpal)
Jakub Hrozek 2012-02-07 14:04:28 UTC Flags needinfo?(jhrozek)
RHEL Program Management 2012-02-07 15:35:34 UTC Status ASSIGNED CLOSED
Resolution --- WONTFIX
Flags needinfo?(dpal)
Last Closed 2012-02-07 10:35:34 UTC
Dmitri Pal 2012-02-10 19:36:32 UTC Status CLOSED ASSIGNED
Resolution WONTFIX ---
Keywords Reopened
Dmitri Pal 2012-03-21 23:33:56 UTC Blocks 791327
K Rain Leander 2012-05-02 08:22:28 UTC CC rleander
Karel Srot 2012-07-11 12:05:37 UTC Summary Rebase sudo to 1.8 in RHEL 6.3 Rebase sudo to 1.8 in RHEL 6.4
Dethlef Madsen 2012-07-12 08:10:14 UTC CC madsen
Siddharth Nagar 2012-07-17 01:21:36 UTC Blocks 840699
Siddharth Nagar 2012-07-17 03:44:30 UTC Blocks 782183
Karel Srot 2012-08-14 07:00:45 UTC Flags needinfo?(jhrozek)
Dominic Cleal 2012-08-14 13:43:39 UTC CC dcleal
Jakub Hrozek 2012-08-14 14:46:54 UTC Flags needinfo?(jhrozek)
Aleš Mareček 2012-09-25 12:30:54 UTC QA Contact qe-baseos-security amarecek
Daniel Kopeček 2012-09-25 15:54:49 UTC Status ASSIGNED MODIFIED
errata-xmlrpc 2012-09-25 15:59:56 UTC Status MODIFIED ON_QA
Daniel Kopeček 2012-09-25 17:53:31 UTC Fixed In Version sudo-1.8.6p3-1.el6
Dennis Gregorovic 2012-11-07 15:35:44 UTC CC dgregor
Jamie Bainbridge 2012-12-10 22:16:21 UTC CC jbainbri
Flags needinfo?(dkopecek)
Daniel Kopeček 2013-01-17 09:35:56 UTC Flags needinfo?(dkopecek)
Dethlef Madsen 2013-01-17 14:22:39 UTC CC madsen
errata-xmlrpc 2013-01-23 01:28:24 UTC Status ON_QA VERIFIED
Daniel Kopeček 2013-01-25 12:08:34 UTC Doc Text Important: if this rebase instead contains *only bug fixes,* or *only enhancements*, select the correct option from the Doc Type drop-down list.

Rebase package(s) to version:
1.8.6p3

Highlights, important fixes or notable enhancements:
- plugin API provided by the new -devel subpackage

- sudoers is now implemented as a policy plugin

- Support for using the System Security Services Daemon (SSSD) as a source of sudoers data

- new configuration file /etc/sudo.conf for sudo frontend configuration (plugin path, coredumps, debugging ...)

- The -D flag in sudo has been replaced with a more general debugging framework that is configured in sudo.conf

- The deprecated "noexec_file" sudoers option is no longer supported

- The "noexec" functionality has been moved out of the sudoers policy plugin and into the sudo front-end, which matches the behavior documented in the plugin writer's guide. As a result the path to the noexec file is now specified in the sudo.conf file instead of the sudoers file

- If a user fails to authenticate and the command would be rejected by sudoers it is now logged with command not allowed instead of N incorrect password attempts. Likewise, the mail_no_perms sudoers option now takes precedence over mail_badpass

- If the user is a member of the exempt group in sudoers they will no longer be prompted for a password even if the -k flag is specified with the command. This makes sudo -k command consistent with the behavior one would get if the user ran sudo -k immediately before running the command.

- If the user specifes a group via sudo's -g option that matches the
target user's group in the password database it is now allowed even if no groups are present in the Runas_Spec.

- A group ID (%#gid) may now be specified in a User_List or
Runas_List. Likewise for non-Unix groups the syntax is %:#gid.

- visudo will now fix the mode on the sudoers file even if no changes are made unless the -f option is specified.
errata-xmlrpc 2013-02-07 00:48:07 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2013-02-21 09:44:01 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2012-02-07 10:35:34 UTC 2013-02-21 04:44:01 UTC
Aleš Mareček 2013-06-05 12:57:15 UTC Blocks 971009

Back to bug 759480