[sudo-users] sudo on Solaris 10 non global zone with Powerbroker Open 7

Martin, Jeff Jeff.Martin at tais.toshiba.com
Wed Jun 27 14:51:59 EDT 2012


Todd,
I am using file based sudoers.
There are no wildcard rules. Its pretty generic.

"/etc/sudoers.tmp" 2 lines, 57 characters
root    ALL=(ALL) ALL
zxxxxxx1       ALL=(ALL) ALL 
zxxxxxx2       ALL=(ALL) ALL

Jeff


-----Original Message-----
From: Todd C. Miller [mailto:Todd.Miller at courtesan.com] 
Sent: Wednesday, June 27, 2012 11:43 AM
To: Martin, Jeff
Cc: sudo-users at sudo.ws
Subject: Re: [sudo-users] sudo on Solaris 10 non global zone with Powerbroker Open 7

On Wed, 27 Jun 2012 10:41:13 PDT, "Martin, Jeff" wrote:

> I have 20 Solaris 10u10 Sparc non-global zones running with Powerbroker
> Open 7 running for AD authentication.
> 
> I have compiled sudo from the source and it work just fine, but users
> are complaining that it takes upwards of 3-5 minutes for the sudo
> command to come back. I am not sure and by no means blaming sudo, I am
> just inquiring if perhaps I missed a compile option or if there is a
> setting that can perhaps be tweaked to get the performance a bit
> quicker. Any ideas/thoughts are appreciated, thanks!

1) Are you using file-based or LDAP-based sudoers?

2) Do you have any rules that use wildcards?  If so, does enabling
   the fast_glob option help?

 - todd


________________________________
This message may contain confidential information.  If you are not the intended recipient of this e-mail, do not disseminate, distribute or copy this e-mail and delete this e-mail from your system.




More information about the sudo-users mailing list