[SSSD-users] Re: sudo for Active Directory group

2017-12-28 Thread Viktor Ekl
Hi, your mean short/fqdn names where ? > We found that there was a Sudo change that requires fqdn for hostnames. Older > versions > used short names. Does having both fqdn and short names make it work? ___ sssd-users mailing list -- sssd-users@lists.fed

[SSSD-users] Re: sudo for Active Directory group

2017-12-28 Thread Viktor Ekl
Hi, User is a member of AD "linux_admin" group. When I run 'id', it doesn't show he is member. By sudo log, do you mean sudo debug log ? I have following there: sudo[1069] sudo_getgrnam: group linux_admin [] -> gid 10001 [] (cached) sudo[1069] sudo_get_gidlist: looking up group IDs for testadmi

[SSSD-users] sudo for Active Directory group

2017-12-22 Thread Viktor Ekl
Hello. Sssd 1.15.2-50 on Centos 7. I'm trying to grant sudo access to members of known AD group (say, "linux_admin"), but with no success: " is not allowed to run sudo on . This incident will be reported" Can't understand why, according to sssd_domain.log group and members found ? My configura