Skip to content

Commit

Permalink
sssd: disable sudo by default
Browse files Browse the repository at this point in the history
SSSD's sudo responder is not enabled by default on Fedora systems,
therefore having it enabled in nsswitch.conf produced warnings in
logs or sudo mails.
  • Loading branch information
pbrezina committed May 9, 2018
1 parent 20f9e91 commit 4b1981a
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 1 deletion.
3 changes: 3 additions & 0 deletions profiles/sssd/README
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,9 @@ with-fingerprint::
with-silent-lastlog::
Do not produce pam_lastlog message during login.

with-sudo::
Allow sudo to use SSSD as a source for sudo rules in addition of /etc/sudoers.

EXAMPLES
--------

Expand Down
2 changes: 1 addition & 1 deletion profiles/sssd/nsswitch.conf
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ group: sss files
netgroup: sss files
automount: sss files
services: sss files
sudoers: files sss
sudoers: files {if "with-sudo":sss}

shadow: files
ethers: files
Expand Down

0 comments on commit 4b1981a

Please sign in to comment.