Hi, The following troubleshooting page may help: https://sssd.io/troubleshooting/sudo.html
On Fri, Jul 17, 2026 at 5:11 PM Andreas Bulling via FreeIPA-users < [email protected]> wrote: > Hi all, > > I've been running FreeIPA without major issues for years, connecting > various Ubuntu machines as clients - most running Ubuntu 24. > > I upgraded three of them to Ubuntu 26 today and noticed that, while I can > still login using SSH (public-key auth), sudo is not working anymore. I > have not touched the sudoers configuration on the FreeIPA server side - I > just updated Ubuntu on these three servers. Those running Ubuntu 24 are > still working fine incl. sudo > > This is what I see in /var/log/auth.log > > 2026-07-17T16:57:52.122663+02:00 cloud sshd-session[3029]: Accepted > publickey for REDACTED from REDACTED port 53988 ssh2: RSA REDACTED > 2026-07-17T16:57:52.138883+02:00 cloud sshd-session[3029]: > pam_unix(sshd:session): session opened for user REDACTED(uid=REDACTED) by > REDACTED(uid=0) > 2026-07-17T16:57:52.162575+02:00 cloud systemd-logind[1387]: New session > '34' of user 'REDACTED' with class 'user' and type 'tty'. > 2026-07-17T16:57:52.213586+02:00 cloud (systemd): > pam_sss(systemd-user:account): Access denied for user REDACTED: 6 > (Permission denied) > 2026-07-17T16:57:52.213829+02:00 cloud (systemd): PAM PAM failed: > Permission denied > > Not sure which other logfiles might be useful for debugging - here are two > that are probably involved: > > # /etc/nsswitch.conf > # > # Example configuration of GNU Name Service Switch functionality. > # If you have the `glibc-doc-reference' and `info' packages installed, try: > # `info libc "Name Service Switch"' for information about this file. > > passwd: files systemd sss > group: files systemd sss > shadow: files sss > gshadow: files > > hosts: files dns > networks: files > > protocols: db files > services: db files sss > ethers: db files > rpc: db files > > netgroup: nis sss > sudoers: files sss > automount: sss > > > ii freeipa-client 4.13.1-1 > amd64 FreeIPA centralized identity framework -- client > ii freeipa-common 4.13.1-1 > all FreeIPA centralized identity framework -- common > files > > sudo -l > sudo: Sorry, user REDACTED may not run sudo on REDACTED. > -- > _______________________________________________ > FreeIPA-users mailing list -- [email protected] > To unsubscribe send an email to [email protected] > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedorahosted.org/archives/list/[email protected] > Do not reply to spam, report it: > https://forge.fedoraproject.org/infra/tickets/issues/new >
-- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
