<font size=2 face="sans-serif">Dear All,</font>
<br>
<br><font size=2 face="sans-serif">I have tried with the settings as mentioned
here. But still the issue persists.</font>
<br>
<br><img src=cid:_1_0B6EB6E00B6EAF20001B9E2F65257D57 style="border:0px solid;">
<br><font size=2 face="sans-serif"><br>
<br>
Regards<br>
Sanju Abraham<br>
IS - Network/System Administrator<br>
Tata Consultancy Services<br>
TCS Centre SEZ Unit,<br>
Infopark PO,<br>
Kochi - 682042,Kerala<br>
India<br>
Ph:- +91 484 6187490<br>
Mailto: sanju.a@tcs.com<br>
Website: </font><a href=http://www.tcs.com/><font size=2 face="sans-serif">http://www.tcs.com</font></a><font size=2 face="sans-serif"><br>
____________________________________________<br>
Experience certainty. IT Services<br>
Business Solutions<br>
Consulting<br>
____________________________________________</font>
<br>
<br>
<br>
<br><font size=1 color=#5f5f5f face="sans-serif">From:
</font><font size=1 face="sans-serif">Tevfik Ceydeliler <tevfik.ceydeliler@astron.yasar.com.tr></font>
<br><font size=1 color=#5f5f5f face="sans-serif">To:
</font><font size=1 face="sans-serif"><freeipa-users@redhat.com></font>
<br><font size=1 color=#5f5f5f face="sans-serif">Date:
</font><font size=1 face="sans-serif">17-09-2014 19:46</font>
<br><font size=1 color=#5f5f5f face="sans-serif">Subject:
</font><font size=1 face="sans-serif">Re: [Freeipa-users]
sudo setup in Ubuntu</font>
<br><font size=1 color=#5f5f5f face="sans-serif">Sent by:
</font><font size=1 face="sans-serif">freeipa-users-bounces@redhat.com</font>
<br>
<hr noshade>
<br>
<br>
<br><font size=3>Thanks to Lukas:</font>
<br><tt><font size=3>Step 0: Install freipa-client on ubuntu 14.04 and
configure sudo integration<br>
</font></tt>
<br><tt><font size=3>root@ubuntu1404:/# ipa-client-install --no-ntp<br>
root@ubuntu1404:/# echo "sudoers: files sss" >> /etc/nsswitch.conf<br>
<br>
root@ubuntu1404:/# grep services /etc/sssd/sssd.conf<br>
services = nss, pam<br>
root@ubuntu1404:/# sed -i -e 's/\(services.*\)/\1, sudo/' /etc/sssd/sssd.conf<br>
root@ubuntu1404:/# grep services /etc/sssd/sssd.conf<br>
services = nss, pam, sudo<br>
<br>
</font></tt>
<br><tt><font size=3>Step 1: configure sudo rules for ordinary user<br>
Please follow the instructions from FreeIPA documentation.<br>
</font></tt><a href="http://www.freeipa.org/docs/master/html-desktop/index.html#sudo"><tt><font size=3 color=blue><u>http://www.freeipa.org/docs/master/html-desktop/index.html#sudo</u></font></tt></a><tt><font size=3><br>
<br>
</font></tt>
<br><tt><font size=3> This step was skipped, becuase it was already
done few months ago <br>
<br>
</font></tt>
<br><tt><font size=3>Step 2: login to machine as ordinary user, which is
allowed to use sudo.<br>
</font></tt>
<br><tt><font size=3>$ su usersssd01<br>
Password:<br>
$ id<br>
uid=325600011(usersssd01) gid=325600011(usersssd01) groups=325600011(usersssd01),30011(biggroup1)<br>
<br>
</font></tt>
<br><tt><font size=3>Step 3: run command<br>
sudo -l<br>
// this command should show you which commands can be executed
as root<br>
// with sudo<br>
</font></tt>
<br><tt><font size=3>$ sudo -l<br>
sudo: unable to resolve host ubuntu1404.example.test<br>
[sudo] password for usersssd01:<br>
Matching Defaults entries for usersssd01 on ubuntu1404:<br>
env_reset, mail_badpass,<br>
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin<br>
<br>
User usersssd01 may run the following commands on ubuntu1404:<br>
(root) /usr/bin/less, /usr/bin/vim<br>
<br>
</font></tt>
<br><tt><font size=3>Step 4: If there weren't any problems then user will
be able to run command.<br>
sudo some_command_listed_in_step3<br>
</font></tt>
<br><tt><font size=3>$ sudo /usr/bin/less /etc/shadow | wc -l<br>
21<br>
$ echo $?<br>
0<br>
<br>
$ sudo apt-get install mc<br>
Sorry, user usersssd01 is not allowed to execute '/usr/bin/apt-get install
mc' as root on ubuntu.example.test.<br>
$ echo $?<br>
1</font></tt>
<br>
<br><font size=3>On 17-09-2014 16:54, Sanju A wrote:</font>
<br><font size=2 face="sans-serif">Dear All,</font><font size=3> <br>
</font><font size=2 face="sans-serif"><br>
I am able to configure the sudo settings in Centos clients by adding/modifying
the entries in /etc/nsswitch.conf and /etc/sudo-ldap.conf. What is
the exact steps for the configuration in Ubuntu as I am not able find the
configuration file sudo-ldap.conf in Ubuntu.</font><font size=3> </font><font size=2 face="sans-serif"><br>
<br>
<br>
Regards<br>
Sanju Abraham<br>
IS - Network/System Administrator<br>
Tata Consultancy Services<br>
TCS Centre SEZ Unit,<br>
Infopark PO,<br>
Kochi - 682042,Kerala<br>
India<br>
Ph:- +91 484 6187490<br>
Mailto: </font><a href=mailto:sanju.a@tcs.com><font size=2 color=blue face="sans-serif"><u>sanju.a@tcs.com</u></font></a><font size=2 face="sans-serif"><br>
Website: </font><a href=http://www.tcs.com/><font size=2 color=blue face="sans-serif"><u>http://www.tcs.com</u></font></a><font size=2 face="sans-serif"><br>
____________________________________________<br>
Experience certainty. IT Services<br>
Business Solutions<br>
Consulting<br>
____________________________________________</font><font size=3> </font>
<p><font size=3>=====-----=====-----=====<br>
Notice: The information contained in this e-mail<br>
message and/or attachments to it may contain <br>
confidential or privileged information. If you are <br>
not the intended recipient, any dissemination, use, <br>
review, distribution, printing or copying of the <br>
information contained in this e-mail message <br>
and/or attachments to it are strictly prohibited. If <br>
you have received this communication in error, <br>
please notify us by reply e-mail or telephone and <br>
immediately and permanently delete the message <br>
and any attachments. Thank you</font>
<p><font size=3><br>
</font>
<br>
<br><font size=3>-- <br>
</font><img src=cid:_4_0B6F0E4C0B6F0BF4001B9E2F65257D57 width=375 height=126 style="border:0px solid;">
<table width=1286 style="border-collapse:collapse;">
<tr height=8>
<td width=1284 bgcolor=white style="border-style:solid;border-color:#000000;border-width:0px 0px 0px 0px;padding:1px 1px;"><font size=3><br>
<br>
<br>
<br>
<br>
<br>
Bu elektronik postada bulunan tum fikir ve gorusler ve ekindeki dosyalar
sadece adres sahip/sahiplerine ait olup, Yasar Toplulugu Sirketleri bu
mesajin icerigi ile ilgili olarak hic bir hukuksal sorumlulugu kabul etmez.
Eger gonderilmesi dusunulen kisi veya kurulus degilseniz, lutfen gonderen
kisiyi derhal haberdar ediniz ve mesaji sisteminizden siliniz.The information
contained in this e-mail and any files transmitted with it are intended
solely for the use of the individual or entity to whom they are addressed
and Yasar Group Companies do not accept legal responsibility for the contents.
If you are not the intended recipient, please immediately notify the sender
and delete it from your system.</font></table>
<br><tt><font size=2>-- <br>
Manage your subscription for the Freeipa-users mailing list:<br>
</font></tt><a href="https://www.redhat.com/mailman/listinfo/freeipa-users"><tt><font size=2>https://www.redhat.com/mailman/listinfo/freeipa-users</font></tt></a><tt><font size=2><br>
Go To </font></tt><a href=http://freeipa.org/><tt><font size=2>http://freeipa.org</font></tt></a><tt><font size=2>
for more info on the project</font></tt>
<br>