[sudo-users] ldap user in multiple sudoRole

Dawei Wang daweiwang at yahoo.com
Fri Oct 28 11:29:01 EDT 2011


I would someone to clarify the behavior of ldap user in multiple sudoRole defined on ldapserver. Turn sudoers_debug on shows that sudo only queries the default and acknowledge(check and verify) the first sudoRole entry returned back by ldap query from sudoer_base.

Is this by design? I remembered somewhere i red stated that you can have users in multiple sudoRole entry.  What is Interesting is that if you do sudo -l, you see entries from all sudoRole the users belongs to.



