Bug 1256788 - Sudo option '!authenticate' not working as expected
Sudo option '!authenticate' not working as expected
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: sssd (Show other bugs)
Unspecified Unspecified
unspecified Severity low
: rc
: ---
Assigned To: Pavel Březina
Kaushik Banerjee
Depends On:
  Show dependency treegraph
Reported: 2015-08-25 08:45 EDT by Abhijeet Kasurde
Modified: 2015-09-28 07:27 EDT (History)
11 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2015-09-16 04:12:13 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
Sudo_rule_log (1.89 KB, text/plain)
2015-08-25 08:45 EDT, Abhijeet Kasurde
no flags Details
sssd_sudo_log (29.75 KB, text/plain)
2015-09-07 03:09 EDT, Abhijeet Kasurde
no flags Details

  None (edit)
Description Abhijeet Kasurde 2015-08-25 08:45:21 EDT
Created attachment 1066838 [details]

Description of problem:
Sudo option !authenticate does not work as per expected. This option allows user to run any sudoer command without providing password.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. kinit admin 
2. ipa sudorule-add files-commands
3. ipa sudorule-add-host --hosts dhcp201-131.testrelm.test files-commands
4. ipa sudorule-add-user --user testuser1  files-commands
5. ipa sudorule-add-allow-command --sudocmds "/usr/bin/less" files-commands 
6. ipa sudorule-add-option files-commands --sudooption '!authenticate'
7. su -c 'sudo -l' testuser1 

Actual results:
testuser1 should use 'sudo' asks for password

Expected results:
testuser1 should use 'sudo' without asking for password

Additional info:
Comment 2 Petr Vobornik 2015-08-25 12:21:43 EDT
Sudo options are enforced by SSSD, changing component.
Comment 3 Pavel Březina 2015-09-01 04:27:14 EDT
Hi, option trouble was always a misconfiguration/misuse so far. I will need sudo logs.
Comment 4 Jakub Hrozek 2015-09-05 11:43:12 EDT
Ping Abhijeet? 

I'm afraid we'd have to close the bug if we can't get the required data..
Comment 5 Abhijeet Kasurde 2015-09-07 03:09:01 EDT
Created attachment 1070843 [details]
Comment 6 Pavel Březina 2015-09-08 06:52:02 EDT
I meant sudo logs, not sssd_sudo.log (sssd sudo responder).
Comment 7 Jakub Hrozek 2015-09-16 04:12:13 EDT
No reply from reporter, closing.
Comment 8 Abhijeet Kasurde 2015-09-28 07:27:06 EDT
Unable to reproduce bug.

Note You need to log in before you can comment on or make changes to this bug.