Re: [Freeipa-users] Sudo issues with FreeIPA

2013-12-23 Thread Dimitar Georgievski
Hi Lukas, Does the LDAP entry need to be removed or just modified? Could the LDAP entry be a sudo policy assigned to the user? In my tests with modified sudo policies the cache entries would persists even after they were invalidated and the user re-authenticated with the LDAP server. Unless I

Re: [Freeipa-users] Sudo issues with FreeIPA

2013-12-23 Thread Lukas Slebodnik
On (23/12/13 10:16), Dimitar Georgievski wrote: Hi Lukas, Does the LDAP entry need to be removed or just modified? Could the LDAP entry be a sudo policy assigned to the user? sudo rules are special case, I didn't noticed anything about sudo rules in the previous mail. There is periodical task in

Re: [Freeipa-users] Sudo issues with FreeIPA

2013-12-21 Thread Lukas Slebodnik
On (20/12/13 18:42), Dimitar Georgievski wrote: Hi Dmitri, One follow up question about the management of the SSSD local cache. I've tried to clean cache entries with the sss_cache utility, but it looks like this utility is not working. I was able to confirm with ldbsearch that records for

Re: [Freeipa-users] Sudo issues with FreeIPA

2013-12-20 Thread Dimitar Georgievski
Hi Dmitri, One follow up question about the management of the SSSD local cache. I've tried to clean cache entries with the sss_cache utility, but it looks like this utility is not working. I was able to confirm with ldbsearch that records for specific entries were not removed from the cache.

Re: [Freeipa-users] Sudo issues with FreeIPA

2013-12-17 Thread Dimitar Georgievski
Thanks Dmitri. Those settings for ldap in sssd.conf fixed the issue. Dimitar On Tue, Dec 17, 2013 at 6:47 PM, Dmitri Pal d...@redhat.com wrote: On 12/17/2013 06:34 PM, Dimitar Georgievski wrote: Hi, I am running FreeIPA 3.3.3 on CentOS 6.5. Everything works fine except that I have