<div dir="ltr"><div>Sean,<br><br>Thanks for the reply. I don't think that's my problem but I'm posting a redacted copy of the sssd.conf file for review below.<br><br><br>[domain/<a href="http://domain.com">domain.com</a>]<br><br>cache_credentials = True<br>krb5_store_password_if_offline = True<br>ipa_domain = <a href="http://domain.com">domain.com</a><br>id_provider = ipa<br>auth_provider = ipa<br>access_provider = ipa<br>ipa_hostname = <a href="http://docker-dev-01.domain.com">docker-dev-01.domain.com</a><br>chpass_provider = ipa<br>ipa_server = _srv_, <a href="http://server.domain.com">server.domain.com</a><br>ldap_tls_cacert = /etc/ipa/ca.crt<br>debug_level=7<br>[sssd]<br>services = nss, sudo, pam, ssh<br>debug_level=7<br>domains = <a href="http://domain.com">domain.com</a><br>[nss]<br>homedir_substring = /home<br><br>[pam]<br><br>[sudo]<br>debug_level=7<br>[autofs]<br><br>[ssh]<br><br>[pac]<br><br>[ifp]<br><br></div>Jeff<br><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Aug 10, 2016 at 2:04 PM, Sean Hogan <span dir="ltr"><<a href="mailto:schogan@us.ibm.com" target="_blank">schogan@us.ibm.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div><p> Not sure it is the same as 14.X but I had to add the sudo in the list of services to sssd.conf as it was not put in by default. I am by no means an expert on it but my own personal experience with 14.x<br><br><br><br>Sean Hogan<br><br><br><br><br><br><img src="cid:1__=88BB0A98DFF086AF8f9e8a93df938690918c88B@" alt="Inactive hide details for Jeff Goddard ---08/10/2016 10:52:31 AM---I've got a freeipa domain and many centos 7.2 clients. I als" border="0" width="16" height="16"><font color="#424282">Jeff Goddard ---08/10/2016 10:52:31 AM---I've got a freeipa domain and many centos 7.2 clients. I also have a sudo rule that allows member of</font><br><br><font color="#5F5F5F" size="2">From: </font><font size="2">Jeff Goddard <<a href="mailto:jgoddard@emerlyn.com" target="_blank">jgoddard@emerlyn.com</a>></font><br><font color="#5F5F5F" size="2">To: </font><font size="2"><a href="mailto:freeipa-users@redhat.com" target="_blank">freeipa-users@redhat.com</a></font><br><font color="#5F5F5F" size="2">Date: </font><font size="2">08/10/2016 10:52 AM</font><br><font color="#5F5F5F" size="2">Subject: </font><font size="2">[Freeipa-users] sudo rules question on ubuntu 16.0.1</font><br><font color="#5F5F5F" size="2">Sent by: </font><font size="2"><a href="mailto:freeipa-users-bounces@redhat.com" target="_blank">freeipa-users-bounces@redhat.<wbr>com</a></font><br></p><hr style="color:#8091a5" align="left" noshade size="2" width="100%"><br><br><br><font size="4">I've got a freeipa domain and many centos 7.2 clients. I also have a sudo rule that allows member of the developer group sudo rights on virtual servers in the "development" group. This works great on the centos servers. However, I recently set up 3 ubuntu boxes, and added them to the IPA domain and then to the "development" group. My sudo rules fail. I've enabled debugging and I see in the /var/log/sssd/sssd_sudo.log that the clients connects to the server, identifies group memberships, and finally prints "returning 1 rules for [</font><a href="mailto:user@domain.com" target="_blank"><u><font color="#0000FF" size="4">user@domain.com</font></u></a><font size="4">]. We only have the single rule so I can't figure out why it's not working. Can someone point me in the correct direction?<br></font><br><font size="4">Thanks,<br></font><br><font size="4">Jeff</font><span class="HOEnZb"><font color="#888888"><br><font size="4"><br></font><tt>-- <br>Manage your subscription for the Freeipa-users mailing list:<br></tt><tt><a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/<wbr>mailman/listinfo/freeipa-users</a></tt><tt><br>Go to </tt><tt><a href="http://freeipa.org" target="_blank">http://freeipa.org</a></tt><tt> for more info on the project</tt><br><br><br>
</font></span><p></p></div>
</blockquote></div><br><br clear="all"><br><br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><br></div><br></div></div>
</div></div>