[sudo-workers] Supporting sudoUser:!foo in sudo.ldap

Michael Felt michael at felt.demon.nl
Tue Dec 14 10:47:21 MST 2021

If you mean add a ! (not) operator, and that it should apply to any combination of any label now used to construct access control logic - imho, that make perfect sense. Stronger, I would think it was a bug when the others did not work.


I think this is worth pursuing.  The question I have is whether supporting !username is sufficient.  If we are going to support this kind of construct, it should probably mirror the existing query that contains uid, groups, gids and netgroups.

Does that make sense?

 - todd
