Re: [Freeipa-users] sudo runs despite being denied by HBAC rules

2016-02-13 Thread Ian Collier
"user NOT in sudoers". Anyway, now I've added an HBAC rule that allows the system staff (but not general users) to run sudo, and this is working too. Sorry for the false alarm. Ian Collier. -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/

[Freeipa-users] sudo runs despite being denied by HBAC rules

2016-02-09 Thread Ian Collier
access, this isn't necessarily a security problem for us. But it's rather puzzling and it does mean a trickle of incoming emails to the sysadmin. The clients here are Fedora 22 with pam 1.1.8, sssd 1.13.3 and sudo 1.8.15. The IPA servers are RHEL 6 with ipa-server 3.0.0. Ian Collier. -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project