# SLES12 SSSD local sudo

**URL:** <https://forums.suse.com/t/sles12-sssd-local-sudo/32291>\
**Category:** SLES Configure-Administer\
**Created:** [April 17, 2018, 6:56pm UTC](https://forums.suse.com/t/sles12-sssd-local-sudo/32291 "2018-04-17T18:56:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tbrinkmann](https://avatars.discourse-cdn.com/v4/letter/t/e99b99/32.png) [@tbrinkmann](https://forums.suse.com/u/tbrinkmann)\
**Post date:** [April 17, 2018, 6:56pm UTC](https://forums.suse.com/t/sles12-sssd-local-sudo/32291/1 "2018-04-17T18:56:42Z")

</div>

Hi there,

we need a very basic sudo configuration for our SLES servers.

All users there are connected through ssh are LDAP-Users over sssd.

We need to allow all LDAP-Users to sudo to ALL=(ALL) ALL

Is it possible to set an ldap group to allow all members of these group to do sudo ?

#\>visudo

%LDAP-User-SERVERNAMEGROUP ALL=(ALL) ALL

Or do we need to save some sodo shemas in our LDAP Server ?

Thanks Tjll

---

<div class="post-metadata">

**Author:** ![thsundel](https://avatars.discourse-cdn.com/v4/letter/t/13edae/32.png) [@thsundel](https://forums.suse.com/u/thsundel)\
**Post date:** [April 18, 2018, 1:49pm UTC](https://forums.suse.com/t/sles12-sssd-local-sudo/32291/2 "2018-04-18T13:49:35Z")

</div>

[QUOTE=tbrinkmann;52185]Hi there,

we need a very basic sudo configuration for our SLES servers.

All users there are connected through ssh are LDAP-Users over sssd.

We need to allow all LDAP-Users to sudo to ALL=(ALL) ALL

Is it possible to set an ldap group to allow all members of these group to do sudo ?

#\>visudo

%LDAP-User-SERVERNAMEGROUP ALL=(ALL) ALL

Or do we need to save some sodo shemas in our LDAP Server ?

Thanks Tjll[/QUOTE]

According to this, that should be enough: [https://www.suse.com/support/kb/doc/?id=7018675](https://www.suse.com/support/kb/doc/?id=7018675)

Thomas

---

<div class="post-metadata">

**Author:** ![tbrinkmann](https://avatars.discourse-cdn.com/v4/letter/t/e99b99/32.png) [@tbrinkmann](https://forums.suse.com/u/tbrinkmann)\
**Post date:** [April 23, 2018, 2:44pm UTC](https://forums.suse.com/t/sles12-sssd-local-sudo/32291/3 "2018-04-23T14:44:31Z")

</div>

Hi Thomas,

thanks for posting the link but how do I can configure this for using LDAP.

For windows Domain it looks like

%DOMAIN\_NAME\GROUP\_NAME

What do I need for our LDAP.

The Search\_base is ou=NUMBER1, ou=NUMBER2, OU=FIRM, O=GERMANY  
plus the group name for the admins ADMIN\_GROUP

Do I need to configure the complete tree ?

Thanks Tjll

---

<div class="post-metadata">

**Author:** ![Lawrence1](https://avatars.discourse-cdn.com/v4/letter/l/e56c9b/32.png) [@Lawrence1](https://forums.suse.com/u/Lawrence1)\
**Post date:** [April 26, 2018, 12:34am UTC](https://forums.suse.com/t/sles12-sssd-local-sudo/32291/4 "2018-04-26T00:34:25Z")

</div>

tbrinkman,

This leads me to ask what LDAP back end you are using, openLDAP or Active Directory for example.

Regardless if your sssd.conf is configured correctly your local groups and your LDAP should both be resolving.

You can test this using standard Linux group tools to test LDAP group name resolution (which should always return the short name, not the distinguished name).

For example, using your provided group name:

~# getent group ADMIN\_GROUP

If you get a successful result that name can be used in your sudo rule/policy:

%ADMIN\_GROUP ALL=(ALL) ALL

Hope it helps!

– lawrence
