# LDAP sudoers / Active Directory / SLES 10

**URL:** <https://forums.suse.com/t/ldap-sudoers-active-directory-sles-10/22916>\
**Category:** SLES Configure-Administer\
**Created:** [August 1, 2012, 11:32am UTC](https://forums.suse.com/t/ldap-sudoers-active-directory-sles-10/22916 "2012-08-01T11:32:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![landism](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@landism](https://forums.suse.com/u/landism)\
**Post date:** [August 1, 2012, 11:32am UTC](https://forums.suse.com/t/ldap-sudoers-active-directory-sles-10/22916/1 "2012-08-01T11:32:39Z")

</div>

Hi All,

I’m trying to set up LDAP based sudoers via AD and have had some success doing so, but run into a problem with passwords. I have successfully extended the Active Directory schema and put in some testing sudoRole entries. Which work fine. However, when I come to run any command e.g. sudo -l will prompt for my password 3 times and not accept the password. SSH uses AD for auth and this works ok. If I add the sudo option to say bypass authentication into AD the sudo itself works fine.

getent groups/passwd return the expected output, although the password for linux enabled users is the default ABCD!efgh12345$67890 which is weird.

Can anyone suggest any pointers at where to look? SSH auth is handled by LDAP to AD over TLS. Happy to provide examples of my ldap.conf and PAM files if necessary

Many Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [August 9, 2012, 3:30pm UTC](https://forums.suse.com/t/ldap-sudoers-active-directory-sles-10/22916/2 "2012-08-09T15:30:34Z")

</div>

landism,

It appears that in the past few days you have not received a response to your  
posting. That concerns us, and has triggered this automated reply.

Has your issue been resolved? If not, you might try one of the following options:

- Visit [http://www.suse.com/support](http://www.suse.com/support) and search the knowledgebase and/or check all  
the other support options available.
- You could also try posting your message again. Make sure it is posted in the  
correct newsgroup. ([http://forums.suse.com](http://forums.suse.com))

Be sure to read the forum FAQ about what to expect in the way of responses:  
[http://forums.suse.com/faq.php](http://forums.suse.com/faq.php)

If this is a reply to a duplicate posting, please ignore and accept our apologies  
and rest assured we will issue a stern reprimand to our posting bot.

Good luck!

Your SUSE Forums Team  
[http://forums.suse.com](http://forums.suse.com)

---

<div class="post-metadata">

**Author:** ![Willem1](https://avatars.discourse-cdn.com/v4/letter/w/c57346/32.png) [@Willem1](https://forums.suse.com/u/Willem1)\
**Post date:** [August 11, 2012, 2:14pm UTC](https://forums.suse.com/t/ldap-sudoers-active-directory-sles-10/22916/3 "2012-08-11T14:14:26Z")

</div>

[QUOTE=landism;5934]Hi All,

I’m trying to set up LDAP based sudoers via AD and have had some success doing so, but run into a problem with passwords. I have successfully extended the Active Directory schema and put in some testing sudoRole entries. Which work fine. However, when I come to run any command e.g. sudo -l will prompt for my password 3 times and not accept the password. SSH uses AD for auth and this works ok. If I add the sudo option to say bypass authentication into AD the sudo itself works fine.

getent groups/passwd return the expected output, although the password for linux enabled users is the default ABCD!efgh12345$67890 which is weird.

Can anyone suggest any pointers at where to look? SSH auth is handled by LDAP to AD over TLS. Happy to provide examples of my ldap.conf and PAM files if necessary  
[/QUOTE]

This is something way beyond what I’ve every configured, but as pointer this might help (if you have not already seen it): [http://www.gratisoft.us/sudo/readme\_ldap.html](http://www.gratisoft.us/sudo/readme_ldap.html)

-Willem
