Bug 761573 - [RFE] Integrate with SUDO utility
[RFE] Integrate with SUDO utility
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: sssd (Show other bugs)
Unspecified Unspecified
high Severity unspecified
: rc
: ---
Assigned To: Jakub Hrozek
Kaushik Banerjee
: FutureFeature
Depends On: 759480 971009
Blocks: 782183 736854 840699
  Show dependency treegraph
Reported: 2011-12-08 11:14 EST by Jakub Hrozek
Modified: 2013-06-05 08:57 EDT (History)
11 users (show)

See Also:
Fixed In Version: sssd-1.9.1-1.el6
Doc Type: Enhancement
Doc Text:
Cause: sudo rules can be stored in a centralized identity store such as LDAP and fetched over the network. Consequence: When the network is not reachable, the sudo client cannot use the rules from the centralized source. Change: A new sudo responder was implemented in the SSSD as well as a client library in the sudo itself. The SSSD is able to act as a transparent proxy for serving the sudo rules for the sudo binary, Result: When the centralized sudo rules source is not available, for instance when the network is down, the SSSD is able to fall back to cached rules, providing transparent access to sudo rules from a centralized database.
Story Points: ---
Clone Of:
: 868943 (view as bug list)
Last Closed: 2013-02-21 04:34:32 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Jakub Hrozek 2011-12-08 11:14:47 EST
Description of problem:
Sudo is able to store its rules in LDAP for easier centralization. However, there is no standardized Name Service Switch Interface and sudo does the lookups on its own.

SSSD will create a new responder/provider pair for downloading and caching SUDO data. A new part of Sudors plugin will be developed that will talk to SSSD using a UNIX socket and fetch the data transparently from SSSD.

The benefits include:
* unified configuration of LDAP servers, timeout parameters, DNS SRV lookups, ...
* only one connection to the LDAP server open
* caching of the sudo rules
* offline access

This feature depends on having a sudo version with pluggable support in RHEL.
Comment 1 Jakub Hrozek 2011-12-08 11:16:54 EST
Upstream ticket:
Comment 5 RHEL Product and Program Management 2012-07-10 03:07:17 EDT
This request was not resolved in time for the current release.
Red Hat invites you to ask your support representative to
propose this request, if still desired, for consideration in
the next release of Red Hat Enterprise Linux.
Comment 8 RHEL Product and Program Management 2012-07-10 22:02:58 EDT
This request was erroneously removed from consideration in Red Hat Enterprise Linux 6.4, which is currently under development.  This request will be evaluated for inclusion in Red Hat Enterprise Linux 6.4.
Comment 12 Nikolai Kondrashov 2012-11-28 06:29:15 EST
Mostly works, but there are still some important bugs.
Comment 13 errata-xmlrpc 2013-02-21 04:34:32 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.