The "sudoers_debug 2" line needs to be in ldap.conf, not /var/ldap/ldap_client_file which uses a different format. You can find the path to ldap.conf that was compiled into your sudo binary by running: sudo -V | grep ldap.conf as root. E.g. # sudo -V | grep ldap.conf ldap.conf path: /etc/ldap.conf - todd