Start a Conversation

Unsolved

This post is more than 5 years old

1453

December 23rd, 2013 02:00

RBAC and sudoers file

Hi all,
Trey to add a user alias with isi_visudo like ‘User_Alias WORM = admin_worm’ as shown below. Because isi_visudo gave access to a part of the sudoers file only (override file) I can’t modify the whole description as shown in /etc/mcp/templates.
Visudo is also no option (sudoers is now auto-generated. To override default behavior, use isi_visudo).
I also can’t overrride e.g User_Alias ADMINS from the sudos profile – so the only way seems to be to add user by user in the override file which isen’t really comfortable.
I am working on a 7.1 release and need support to find the ‘clean’ way to do such a modification ;-))

/etc/mcp/override/sudoers.tmp: 16 lines, 511 characters.
ISI-CL-1# visudo sudoers is now auto-generated.
To override default behavior, use isi_visudo.
I SI-CL-1
# isi_visudo
## Sudoers override file.
##
## This file overrides the default configuration for sudo as provided by
## Isilon. The defaults can be found at /etc/mcp/templates/sudoers. Do not
## edit /etc/mcp/templates/sudoers.
##
## To add additional command permissions, enter the appropriate configuration
## lines below. To remove a command provided by default, enter a negation line
## below.
##
## Example:
##
## To prevent admin from running SyncIQ, uncomment the line below:
## admin ALL=(ALL) !/usr/bin/isi sync*
##
User_Alias WORM = admin_worm
~ /etc/mcp/override/sudoers.tmp: 16 lines, 539 characters.
isi_visudo: Warning: unused User_Alias WORM

No Responses!
No Events found!

Top