Bug 2100960
| Summary: | adding user to the wheel group does not permit sudo access | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Alok Sharma <alsharma> |
| Component: | sudo | Assignee: | Radovan Sroka <rsroka> |
| Status: | CLOSED MIGRATED | QA Contact: | BaseOS QE Security Team <qe-baseos-security> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 8.5 | CC: | dapospis |
| Target Milestone: | rc | Keywords: | MigratedToJIRA, Triaged |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-08-16 14:42:13 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
Thanks -- this all looks expected. At this point I'm afraid I don't know how to debug this further. sudo maintainers, is there a way to make sudo more verbose? This bug is going to be migrated. Contact point for migration questions or issues: rsroka Guidance for Bugzilla users to test their Jira account or create one if needed: https://redhat.service-now.com/help?id=kb_article_view&sysparm_article=KB0016394 https://redhat.service-now.com/help?id=kb_article_view&sysparm_article=KB0016694 https://redhat.service-now.com/help?id=kb_article_view&sysparm_article=KB0016774 |
This should not (primarily) depend on authselect. ID 1022 sounds like a local user, not one centrally managed by FreeIPA. Do you have some customized sudoers file? The default /etc/sudoers has this rule: ## Allows people in group wheel to run all commands %wheel ALL=(ALL) ALL Does that exist for you? If so, then this is somehow a sudo bug (and I'll reassign). Otherwise, do you remember customizing it? If you definitively didn't, I'll reassign to authselect. Cockpit does not touch sudoers, and IMHO the UI is rightful to assume that wheel membership means administrative rights, as per documentation [1]. Thanks! [1] https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/configuring_basic_system_settings/managing-sudo-access_configuring-basic-system-settings