John, Thanks for all the info. I'm running a very similar setup but I'm still using the legacy sudo-ldap.conf for my sudo info, I'll install sudo-sss and give that a whirl. Dan On May 22, 2013, at 8:09 PM, Jonathan Vaughn <jonathan@xxxxxxxxxxxxx> wrote: we're using sssd for Kerberos logins with LDAP user account details, and it's caching sudo LDAP for us too. I'm not sure off hand if it'll work with nested groups if you use them - we haven't used nested groups on any of the groups we've used with sudo (due to other various programs failing to support either recursing through groups or using the memberof attribute on the user). |
-- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users