Re: LDAP defaults for commands

"Todd C. Miller" <[email protected]>
Newsgroups gmane.comp.tools.sudo.user
Message-ID <[email protected]>
Another way to achieve this is to use a sudoRole object that contains
the commands for which you wish to disable execute and give it a
large value sudoOrder attribute.  You still have to assign users
to the sudoRole but the more restrictive role will be the one to
match.  For example, something like the following will override
rules with a lower sudoOrder (which defaults to 0).

dn: cn=pagers,ou=SUDOers,dc=sudo,dc=ws
objectClass: top
objectClass: sudoRole
cn: pagers
sudoUser: millert
sudoRunAsUser: ALL
sudoRunAsGroup: ALL
sudoHost: ALL
sudoCommand: /usr/bin/less
sudoCommand: /usr/bin/more
sudoCommand: /usr/bin/pg
sudoOption: noexec
sudoOrder: 1000
____________________________________________________________
sudo-users mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.