IPA sudo rule applied on hostgroup does not work on IPA client

Solution Verified - Updated -

Issue

  • When creating a sudo rule, limiting the sudo rule to individual hosts works. However when adding the same systems to a hostgroup and using this instead the sudo command fails with message:
Sorry, user username is not allowed to execute 'command' as root on servername
  • In IPA environment, sudo doesn't work on IPA client which is part of a hostgroup where sudorule is applied on hostgroup in IPA.

  • sudorules applied on IPA hostgroup do not work on certain IPA clients.

Environment

  • Red Hat Enterprise Linux 6
  • Red Hat Enterprise Linux 7
  • Red Hat Enterprise Linux 8
  • IPA
  • sudo
  • sssd

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content