Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-109179

Host group "ipaservers" can be specified in sudo rule but will cause sudo rule to fail

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • rhel-10.2
    • rhel-8.10
    • ipa
    • No
    • Low
    • 1
    • rhel-idm-ipa
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • IPA: RHELs for 10.2 and 9.8
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      Via the IdM Web UI, a sudo rule can be constructed that specifies the rule should apply to the "ipaservers" host group. However, because this group does not have a matching nisNetGroup, the sudo rule will not provide the expected access. Running the sudo command on one of the servers in the ipaservers group will simply result in a failure.

      What is the impact of this issue to you?

      From an end-user perspective, creating sudo rules against a default group in idM should 'just work' and not require workarounds. The bug is obscure and it can take hours to determine the cause.

      Please provide the package NVR for which the bug is seen:

      ipa-server-4.9.13-18
      ipa-server-common-4.9.13-18

      How reproducible is this bug?:

      Every time

      Steps to reproduce

      1. Create a sudo rule that specifies "ipaservers" in the "Access this host: Host Groups" section
      2. SSH into an IPA server (member of "ipaservers" group) as a user affected by that sudo rule
      3. Attempt to use sudo command (e.g., 'sudo -l') and see failure.
      4. Change rule from "ipaservers" to any other group, or explicitly listing specific individual servers, or simply "Any Host", and 'sudo -l' succeeds.

      Expected results

      sudo should succeed

      Actual results

      sudo on client fails

              frenaud@redhat.com Florence Renaud
              rhn-support-rlundgren Runar Lundgren
              Florence Renaud Florence Renaud
              Sudhir Menon Sudhir Menon
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: