Re: [Freeipa-users] Best place to start debugging sudo issue

2013-10-01 Thread Bret Wortman
Thanks. In this case, on a lark, I compared the sizes of the ca.crt file between the working and nonworking nodes and there was a 4 byte difference. Copying over the working copy to the nonworking node got things flowing again. I'm filing these notes in my nv stack for later reference, though. Tha

Re: [Freeipa-users] Best place to start debugging sudo issue

2013-10-01 Thread Rob Crittenden
Bret Wortman wrote: One some of my nodes, attempting to sudo yields this: $ sudo su - sudo: ldap_start_tls_s(): Connect error [sudo] password for bretw: When the policy for my account is set up for !authenticate on all systems. On my own workstation, and most of our systems, it works just fine