SUDOERS.LDAP(5) (NAME) sudoers.ldap - sudoers LDAP (DESCRIPTION) sudoers.ldap sudo LDAP . sudoers sudo LDAP . sudoers . LDAP sudoers : o sudo sudoers . LDAP LDAP . LDAP . o (override) . /etc/sudoers . . . o visudo . visudo /etc/sudoers . LDAP () . LDAP . LDAP SUDOers (SUDOers LDAP container) sudoers () LDAP `ou=SUDOers' . sudo `cn=defaults' SUDOers . sudoOption Defaults /etc/sudoers . SSH_AUTH_SOCK : dn: cn=defaults,ou=SUDOers,dc=my-domain,dc=com objectClass: top objectClass: sudoRole cn: defaults description: Default sudoOption's go here sudoOption: env_keep+=SSH_AUTH_SOCK sudoer LDAP sudoRole . : sudoUser ( `#') ( `%' `%#') ( `+') ( `%:' `%:#'). . group_plugin defaults sudoRole . sudoUser (`!') sudoRole . sudoUser .. . sudoHost IP IP ( `+'). ALL . ( ) . sudoHost (`!') sudoRole . sudoHost .. . sudoCommand (). (`!') . "sudoedit" sudo -e ( sudoedit) . . "sudoedit" sudo . ALL . SHA-2 . sudo . : sha224 sha256 sha384 sha512. (`:') base64 . sudoCommand: sha224:0GomF8mNN3wlDt1HD9XldjJ3SNgpFdbjO1+NsQ /bin/ls /bin/ls sha224 . .. . sudoOption sudoRole . sudoRunAsUser ( `#') ( `%') ( `+') . ALL . sudoRunAsUser (`!') sudoRole . sudoRunAsUser . sudoRunAsUser sudoRunAsGroup sudoOption runas_default ( root ). sudoRunAsUser .. sudo . sudo sudoRunAs . sudoRunAsUser .. . sudoRunAsGroup ( `#') . ALL . sudoRunAsGroup (`!') sudoRole . sudoRunAsGroup .. sudo . sudoRunAsGroup .. . sudoNotBefore `yyyymmddHHMMSSZ' sudoRole . sudoNotBefore . (UTC) . LDAP RFC . sudoNotBefore .. sudo SUDOERS_TIMED /etc/openldap/ldap.conf . sudoNotAfter `yyyymmddHHMMSSZ' / sudoRole . sudoNotAfter . (UTC) . LDAP . sudoNotAfter .. sudo SUDOERS_TIMED /etc/openldap/ldap.conf . sudoOrder sudoRole LDAP . sudoOrder ( ) . sudoers LDAP sudoers . sudoOrder . << >> (last match) sudoers . sudoOrder . sudoOrder .. sudo . . sudoRole sudoUser sudoHost sudoCommand . wheel sudo : dn: cn=%wheel,ou=SUDOers,dc=my-domain,dc=com objectClass: top objectClass: sudoRole cn: %wheel sudoUser: %wheel sudoHost: ALL sudoCommand: ALL sudoers LDAP (Anatomy of LDAP sudoers lookup) sudoer LDAP LDAP . . . ( ALL .) . SUDOERS_TIMED LDAP . NETGROUP_BASE NETGROUP_QUERY ( ldap.conf ) sudoers . sudoers . . LDAP sudo : 1. nisNetgroup nisNetgroupTriple NIS. nisNetgroupTriple . NIS . NIS (wildcard) NIS LDAP nisNetgroupTriple . 2. nisNetgroup memberNisNetgroup . NETGROUP_BASE sudo LDAP nisNetgroup nisNetgroupTriple . sudoers LDAP (Differences between LDAP and non-LDAP sudoers) LDAP sudoers LDAP (Aliases) sudo . sudo . ( group_plugin) User_Aliases Runas_Aliases . Host_Aliases . LDAP sudo . sudoers LDAP . RFC LDAP . sudoOrder . () . (paranoid) ( ). : # /etc/sudoers: # Allow all commands except shell johnny ALL=(root) ALL,!/bin/sh # Always allows all commands because ALL is matched last puddles ALL=(root) !/bin/sh,ALL # LDAP equivalent of johnny # Allows all commands except shell dn: cn=role1,ou=Sudoers,dc=my-domain,dc=com objectClass: sudoRole objectClass: top cn: role1 sudoUser: johnny sudoHost: ALL sudoCommand: ALL sudoCommand: !/bin/sh # LDAP equivalent of puddles # Notice that even though ALL comes last, it still behaves like # role1 since the LDAP code assumes the more paranoid configuration dn: cn=role2,ou=Sudoers,dc=my-domain,dc=com objectClass: sudoRole objectClass: top cn: role2 sudoUser: puddles sudoHost: ALL sudoCommand: !/bin/sh sudoCommand: ALL sudoers LDAP (Converting between file-based and LDAP sudoers) cvtsudoers(1) sudoers LDAP . sudoers sudoers LDAP ( ). . Cmnd_Alias sudoers sudoRole . / sudoRole . Defaults runas . sudoRole sudoOption . sudoers : Cmnd_Alias PAGERS = /usr/bin/more, /usr/bin/pg, /usr/bin/less Defaults!PAGERS noexec alice, bob ALL = ALL alice bob PAGERS noexec (shell escape) . LDAP sudoRole : dn: cn=PAGERS,ou=SUDOers,dc=my-domain,dc=com objectClass: top objectClass: sudoRole cn: PAGERS sudoUser: alice sudoUser: bob sudoHost: ALL sudoCommand: /usr/bin/more sudoCommand: /usr/bin/pg sudoCommand: /usr/bin/less sudoOption: noexec sudoOrder: 900 dn: cn=ADMINS,ou=SUDOers,dc=my-domain,dc=com objectClass: top objectClass: sudoRole cn: ADMINS sudoUser: alice sudoUser: bob sudoHost: ALL sudoCommand: ALL sudoOrder: 100 LDAP sudoOrder sudoRole PAGERS noexec . sudoers LDAP sudoRole PAGERS . PAGERS . Defaults sudoOption sudoRole . sudoers : User_Alias ADMINS = john, sally Defaults:ADMINS !authenticate ADMINS ALL = (ALL:ALL) ALL john sally . LDAP User_Alias : dn: cn=admins,ou=SUDOers,dc=my-domain,dc=com objectClass: top objectClass: sudoRole cn: admins sudoUser: %admin sudoHost: ALL sudoRunAsUser: ALL sudoRunAsGroup: ALL sudoCommand: ALL sudoOption: !authenticate john sally "admins' . Sudoers (Sudoers schema) LDAP sudo () sudo LDAP . sudoUser . sudo sudoers LDAP : schema.ActiveDirectory (Microsoft Active Directory) schema.IBM_LDAP (IBM Directory Server) IBM Tivoli Directory Server IBM Security Directory Server IBM Security Verify Directory schema.iPlanet iPlanet Oracle 389 Directory Server schema.olcSudo OpenLDAP slapd . (on-line) schema.OpenLDAP OpenLDAP slapd OpenBSD ldapd OpenLDAP (EXAMPLES) . ldap.conf (Configuring ldap.conf) sudo /etc/openldap/ldap.conf LDAP . LDAP . sudo . /etc/openldap/ldap.conf sudo ldap.conf(5) . ldap.conf ldap_conf sudo.conf(5) . OpenLDAP /etc/openldap/ldap.conf .ldaprc . sudo LDAP OpenLDAP Netscape ( Solaris HP-UX ) IBM LDAP ( Tivoli). LDAP . . /etc/openldap/ldap.conf sudo . . (`#') . . BIND_TIMELIMIT seconds BIND_TIMELIMIT ( ) LDAP . URI HOST . BINDDN DN BINDDN LDAP (DN) . LDAP (anonymous) . LDAP . BINDPW secret BINDPW LDAP . BINDDN . secret Base64 "base64:" . : BINDPW base64:dGVzdA== . (`#') (`\') . DEREF never/searching/finding/always (alias dereferencing) . ldap.conf(5) . HOST name[:port] ... URI ( ) HOST LDAP . (`:') . HOST URI . KRB5_CCNAME file name (Kerberos 5 credential cache) . SASL ( ). LDAP_VERSION number LDAP . . NETGROUP_BASE base DN LDAP. my-domain.com `ou=netgroup,dc=my-domain,dc=com' . NETGROUP_BASE . sudo sudoRole innetgr() C LDAP . NETGROUP_QUERY ( ) LDAP sudoers . sudoRole sudoUser `+' . NIS LDAP nisNetgroup nisNetgroupTriple . slapd OpenLDAP nisNetgroupTriple : attributetype ( 1.3.6.1.1.1.1.14 NAME 'nisNetgroupTriple' DESC 'Netgroup triple' EQUALITY caseIgnoreIA5Match SUBSTR caseIgnoreIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 ) NETGROUP_BASE LDAP nisNetgroupTriple . ldapsearch: $ ldapsearch -b $NETGROUP_BASE \ '(&(objectClass=nisNetgroup)(nisNetgroupTriple=\28*,USER,\29))' nisNetgroup nisNetgroupTriple : nisNetgroupTriple: (,USER,) NETGROUP_QUERY on/true/yes/off/false/no NETGROUP_QUERY LDAP nisNetgroup nisNetgroupTriple . sudoers NETGROUP_BASE nisNetgroupTriple LDAP . NETGROUP_QUERY sudoers NETGROUP_BASE . innetgr() . NETGROUP_BASE . NETGROUP_SEARCH_FILTER ldap_filter LDAP LDAP . `attribute=value' `(&(attribute=value)(attribute2=value2))' . : `objectClass=nisNetgroup'. ldap_filter . LDAP . NETWORK_TIMEOUT seconds BIND_TIMELIMIT OpenLDAP. PORT port_number URI PORT LDAP HOST . PORT LDAP LDAP TLS (SSL) . PORT URI . ROOTBINDDN DN ROOTBINDDN (DN) LDAP sudoers . ldap_secret sudo.conf(5) /etc/ldap.secret . ROOTBINDDN BINDDN ( ) . ROOTUSE_SASL on/true/yes/off/false/no ROOTUSE_SASL SASL LDAP sudo . SASL_AUTH_ID identity SASL LDAP. sudo . SASL . SASL_MECH mechanisms SASL . sudo GSSAPI . SASL_SECPROPS none/properties SASL none . SASL . SASL . SSL on/true/yes/off/false/no SSL on true yes TLS (SSL) LDAP . (ldaps) . SSL start_tls SSL start_tls LDAP TLS bind . . LDAP start_tls OpenLDAP IBM Tivoli. SUDOERS_BASE base DN sudo LDAP. my-domain.com `ou=SUDOers,dc=my-domain,dc=com' . SUDOERS_BASE . SUDOERS_DEBUG debug_level () sudo LDAP . . . . . SUDOERS_DEBUG . sudo "ldap" diag info debug_level . sudo sudo.conf(5) . SUDOERS_SEARCH_FILTER ldap_filter LDAP sudo LDAP . `attribute=value' `(&(attribute=value)(attribute2=value2))' . : `objectClass=sudoRole'. ldap_filter . SUDOERS_TIMED on/true/yes/off/false/no sudoNotBefore sudoNotAfter sudoers . TIMELIMIT seconds TIMELIMIT ( ) LDAP . TIMEOUT seconds TIMEOUT ( ) API LDAP . TLS_CACERT file name TLS_CACERTFILE OpenLDAP. TLS_CACERTFILE file name (CA bundle) /etc/ssl/ca-bundle.pem. OpenLDAP . LDAP Netscape CA ( TLS_CERT ). TLS_CACERTDIR directory TLS_CACERTFILE /etc/ssl/certs. TLS_CACERTDIR TLS_CACERTFILE . OpenLDAP . TLS_CERT file name LDAP . LDAP . OpenLDAP: `tls_cert /etc/ssl/client_cert.pem' Netscape: `tls_cert /var/ldap/cert7.db' IBM LDAP: TLS_KEY . Netscape (CA) . TLS_CHECKPEER on/true/yes/off/false/no TLS_CHECKPEER TLS LDAP . TLS ( ) sudo . TLS_CHECKPEER . (man-in- the-middle) . CA . IBM LDAP . TLS_KEY file name TLS_CERT . . LDAP . OpenLDAP: `tls_key /etc/ssl/client_key.pem' Netscape: `tls_key /var/ldap/key3.db' IBM LDAP: `tls_key /usr/ldap/ldapkey.kdb' IBM LDAP . TLS_CIPHERS cipher list TLS_CIPHERS TLS (SSL) . OpenLDAP IBM Tivoli Directory Server . Netscape . TLS_KEYPW secret IBM LDAP . secret Base64 "base64:" . : TLS_KEYPW base64:dGVzdA== . (`#') (`\') . /etc/openldap/ldap.conf . stash file ( ). TLS_KEYPW stash file . stash file TLS_KEY `.sth' `.kdb' `ldapkey.sth'. `ldapkey.kdb' IBM Tivoli Directory Server `ssl_password' . gsk8capicmd stash file . IBM LDAP . TLS_REQCERT level TLS_REQCERT TLS LDAP ( ). TLS ( ) sudo . level : never . allow . . try . . demand | hard . . . OpenLDAP . LDAP TLS_CHECKPEER . TLS_RANDFILE file name TLS_RANDFILE . prngd egd . OpenLDAP . URI ldap[s]://[hostname[:port]] ... URI () LDAP . protocol ldap ldaps TLS (SSL) . `ldap://' `ldaps://' . sudo localhost . URI URI . OpenSSL URI `ldap://' `ldaps://' . Netscape IBM LDAP . USE_SASL on/true/yes/off/false/no USE_SASL LDAP SASL . ROOTSASL_AUTH_ID identity SASL ROOTUSE_SASL . ldap.conf (EXAMPLES) . nsswitch.conf (Configuring nsswitch.conf) sudo Name Service Switch /etc/nsswitch.conf sudoers . sudo sudoers: . sudo ( `[SUCCESS=return]' ). : files sudoers /etc/sudoers ldap sudoers LDAP nsswitch.conf `[SUCCESS=return]' `[NOTFOUND=return]'. (`[SUCCESS=return]') (`[NOTFOUND=return]'). `!' . LDAP sudoers ( ) : sudoers: ldap files LDAP sudoers ( ) : sudoers: files [SUCCESS=return] ldap sudoers : sudoers: ldap /etc/nsswitch.conf sudoers : sudoers: files /etc/nsswitch.conf sudo AIX ( ). netsvc.conf (Configuring netsvc.conf) AIX /etc/netsvc.conf /etc/nsswitch.conf . sudo netsvc.conf nsswitch.conf . LDAP sudoers ( ) : sudoers = ldap, files sudoers : sudoers = ldap LDAP sudoers LDAP : sudoers = ldap = auth, files auth LDAP sudoers Defaults . /etc/netsvc.conf sudoers : sudoers = files sssd (Integration with sssd) System Security Services Daemon (SSSD) sudo SSSD SSSD LDAP sudoers . SSSD sudoers sss ldap sudoers /etc/nsswitch.conf . /etc/openldap/ldap.conf SSSD sudo . sudo SSSD sssd-sudo(5) . (FILES) /etc/openldap/ldap.conf LDAP /etc/nsswitch.conf sudoers /etc/netsvc.conf sudoers AIX (EXAMPLES) ldap.conf (Example ldap.conf) # Either specify one or more URIs or one or more host:port pairs. # If neither is specified sudo will default to localhost, port 389. # #host ldapserver #host ldapserver1 ldapserver2:390 # # Default port if host is specified without one, defaults to 389. #port 389 # # URI will override the host and port settings. uri ldap://ldapserver #uri ldaps://secureldapserver #uri ldaps://secureldapserver ldap://ldapserver # # The amount of time, in seconds, to wait while trying to connect to # an LDAP server. bind_timelimit 30 # # The amount of time, in seconds, to wait while performing an LDAP query. timelimit 30 # # Must be set or sudo will ignore LDAP; may be specified multiple times. sudoers_base ou=SUDOers,dc=my-domain,dc=com # # verbose sudoers matching from ldap #sudoers_debug 2 # # Enable support for time-based entries in sudoers. #sudoers_timed yes # # optional proxy credentials #binddn #bindpw #rootbinddn # # LDAP protocol version, defaults to 3 #ldap_version 3 # # Define if you want to use an encrypted LDAP connection. # Typically, you must also set the port to 636 (ldaps). #ssl on # # Define if you want to use port 389 and switch to # encryption before the bind credentials are sent. # Only supported by LDAP servers that support the start_tls # extension such as OpenLDAP. #ssl start_tls # # Additional TLS options follow that allow tweaking of the # SSL/TLS connection. # #tls_checkpeer yes # verify server SSL certificate #tls_checkpeer no # ignore server SSL certificate # # If you enable tls_checkpeer, specify either tls_cacertfile # or tls_cacertdir. Only supported when using OpenLDAP. # #tls_cacertfile /etc/certs/trusted_signers.pem #tls_cacertdir /etc/certs # # For systems that don't have /dev/random # use this along with PRNGD or EGD.pl to seed the # random number pool to generate cryptographic session keys. # Only supported when using OpenLDAP. # #tls_randfile /etc/egd-pool # # You may restrict which ciphers are used. Consult your SSL # documentation for which options go here. # Only supported when using OpenLDAP. # #tls_ciphers # # Sudo can provide a client certificate when communicating to # the LDAP server. # Tips: # * Enable both lines at the same time. # * Do not password protect the key file. # * Ensure the keyfile is only readable by root. # # For OpenLDAP: #tls_cert /etc/certs/client_cert.pem #tls_key /etc/certs/client_key.pem # # For Netscape-derived LDAP, tls_cert and tls_key may specify either # a directory, in which case the files in the directory must have the # default names (e.g., cert8.db and key4.db), or the path to the cert # and key files themselves. However, a bug in version 5.0 of the LDAP # SDK will prevent specific file names from working. For this reason # it is suggested that tls_cert and tls_key be set to a directory, # not a file name. # # The certificate database specified by tls_cert may contain CA certs # and/or the client's cert. If the client's cert is included, tls_key # should be specified as well. # For backward compatibility, "sslpath" may be used in place of tls_cert. #tls_cert /var/ldap #tls_key /var/ldap # # If using SASL authentication for LDAP (OpenSSL) # use_sasl yes # sasl_auth_id # rootuse_sasl yes # rootsasl_auth_id # sasl_secprops none # krb5_ccname /etc/.ldapcache Sudoers OpenLDAP (Sudoers schema for OpenLDAP) OpenLDAP sudo schema.OpenLDAP . ( /etc/openldap/schema) include slapd.conf slapd . OpenLDAP . schema.olcSudo . attributetype ( 1.3.6.1.4.1.15953.9.1.1 NAME 'sudoUser' DESC 'User(s) who may run sudo' EQUALITY caseExactMatch SUBSTR caseExactSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) attributetype ( 1.3.6.1.4.1.15953.9.1.2 NAME 'sudoHost' DESC 'Host(s) who may run sudo' EQUALITY caseExactIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 ) attributetype ( 1.3.6.1.4.1.15953.9.1.3 NAME 'sudoCommand' DESC 'Command(s) to be executed by sudo' EQUALITY caseExactIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 ) attributetype ( 1.3.6.1.4.1.15953.9.1.4 NAME 'sudoRunAs' DESC 'User(s) impersonated by sudo' EQUALITY caseExactIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 ) attributetype ( 1.3.6.1.4.1.15953.9.1.5 NAME 'sudoOption' DESC 'Options(s) followed by sudo' EQUALITY caseExactIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 ) attributetype ( 1.3.6.1.4.1.15953.9.1.6 NAME 'sudoRunAsUser' DESC 'User(s) impersonated by sudo' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) attributetype ( 1.3.6.1.4.1.15953.9.1.7 NAME 'sudoRunAsGroup' DESC 'Group(s) impersonated by sudo' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) attributetype ( 1.3.6.1.4.1.15953.9.1.8 NAME 'sudoNotBefore' DESC 'Start of time interval for which the entry is valid' EQUALITY generalizedTimeMatch ORDERING generalizedTimeOrderingMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 ) attributetype ( 1.3.6.1.4.1.15953.9.1.9 NAME 'sudoNotAfter' DESC 'End of time interval for which the entry is valid' EQUALITY generalizedTimeMatch ORDERING generalizedTimeOrderingMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 ) attributetype ( 1.3.6.1.4.1.15953.9.1.10 NAME 'sudoOrder' DESC 'an integer to order the sudoRole entries' EQUALITY integerMatch ORDERING integerOrderingMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 ) objectclass ( 1.3.6.1.4.1.15953.9.2.1 NAME 'sudoRole' SUP top STRUCTURAL DESC 'Sudoer Entries' MUST ( cn ) MAY ( sudoUser $ sudoHost $ sudoCommand $ sudoRunAs $ sudoRunAsUser $ sudoRunAsGroup $ sudoOption $ sudoNotBefore $ sudoNotAfter $ sudoOrder $ description ) ) (SEE ALSO) cvtsudoers(1), ldap.conf(5), sssd-sudo(5), sudo.conf(5), sudoers(5) (AUTHORS) sudo : Todd C. Miller sudo CONTRIBUTORS.md sudo (https://www.sudo.ws/about/contributors) . (CAVEATS) sudoers LDAP sudoers . sudoers LDAP . (BUGS) sudoers.ldap sudo https://bugzilla.sudo.ws issue https://github.com/sudo- project/sudo/issues . sudo- workers https://www.sudo.ws/mailman/listinfo/sudo-workers () () . issue Bugzilla . . https://www.sudo.ws/dist/PGPKEYS PGP . (SUPPORT) sudo-users https://www.sudo.ws/mailman/listinfo/sudo-users . (DISCLAIMER) sudo << >> (AS IS) . LICENSE.md sudo https://www.sudo.ws/about/license . sudo SUDOERS.LDAP(5)