Description of problem:
After upgrading to the latest version of sudo, ldap and local users are not able to sudo
Version-Release number of selected component (if applicable):
sudo-1.8.19p2-10.el7.x86_64
How reproducible:
Everytime
Steps to Reproduce:
1. sudo su -
Actual results:
<username> is not in the sudoers file. This incident will be reported.
Expected results:
Able to run sudo commands
Comment 43Michael Starling
2017-09-12 14:54:27 UTC
I see this issue with the LDAP backend. We do not use the SSSD backend because it doesn't respect the sudo option "!root_sudo". We also like to keep our standard bind user in sssd.conf different from the user that searches for SUDO rules in /etc/sudo-ldap.conf. We have also found that we are unable to restrict ACLs as tightly for the bind user in sssd.conf as we are in sudo-ldap.conf.