You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RHEL9系统中Nsswitch配置sudoers使用SSSD替代LDAP失效问题排查求助

RHEL9系统中Nsswitch配置sudoers使用SSSD替代LDAP失效问题排查求助

大家好,我遇到个头疼的问题想请教下:我在RHEL9系统上尝试把nsswitch里的sudoers配置成files sss(这本来是RHEL9的默认配置),但这么设置后sudo完全没法正常工作;反而改成files ldap就一切正常。

我已经能通过自己的账号成功登录实例,而且LDAP里的sudo规则明明设置了sudoCommand: ALL,就是没法获取sudo权限。想问问各位,我在SSSD的配置上是不是漏掉了什么?

以下是我整理的相关信息:

LDAP sudo规则查询结果

执行命令:

$ ldapsearch -H ldap://ipa.example.com -b ou=sudoers,dc=example,dc=com -ZZ '(&(objectClass=sudoRole))' -x

输出:

# allow_all, sudoers, EXAMPLE.COM
dn: cn=allow_all,ou=sudoers,dc=EXAMPLE,dc=COM
objectClass: sudoRole
objectClass: top
sudoUser: %host-admin
sudoHost: ALL
sudoCommand: ALL
sudoRunAsUser: ALL
sudoRunAsGroup: ALL
cn: allow_all

当前用户身份信息

执行命令:

$ id admin

输出:

uid=6666(admin),1234(host-admins)

SSSD配置文件(/etc/sssd/sssd.conf)

[domain/default]
id_provider = ldap
auth_provider = ldap
sudo_provider = ldap
chpass_provider = ldap
ldap_uri = ldaps://ipa.example.com
ldap_search_base = dc=example,dc=com
ldap_id_use_start_tls = True
ldap_schema = rfc2307bis
ldap_sudo_include_regexp = true
cache_credentials = True
ldap_tls_cacertdir = /etc/openldap/certs
ldap_tls_reqcert = allow

[sssd]
services = nss, pam, sudo
domains = default

[nss]
homedir_substring = /home

[pam]

[sudo]
debug_level = 7

Nsswitch配置对比

  • 失效配置:sudoers: files sss
  • 正常配置:sudoers: files ldap

麻烦各位帮我排查下问题所在,谢谢大家!

备注:内容来源于stack exchange,提问作者N. J

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 10:24:30