[sudo-users] Checksum for executed scripts

Todd C. Miller Todd.Miller at courtesan.com
Tue Aug 20 10:41:19 MDT 2013


On Tue, 20 Aug 2013 16:20:05 -0000, JR Aquino wrote:

> Can this be expressed in LDAP as well?

Yes, you just put the digest before the command.  E.g.

LDAP Role: millert
    RunAsUsers: ALL
    RunAsGroups: ALL
    Options: !authenticate, runas_default=nobody
    Order: 5
    Commands:
	sha224:d06a2617c98d377c250edd470fd5e576327748d82915d6e33b5f8db1 /bin/ls

 - todd


More information about the sudo-users mailing list