sudoers compat plugin configuration missed the sudoOrder attribute and it thus does not show up in the ou=sudoers.
sudoOrder
ou=sudoers
To hotfix it, I did:
# ldapmodify -h `hostname` -D "cn=Directory Manager" -x -W dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config changetype: modify add: schema-compat-entry-attribute schema-compat-entry-attribute: sudoOrder=%{sudoOrder} modifying entry "cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config"
sudoOrder was then fixed.
Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1052983
attachment freeipa-mkosek-446-sudoorder-missing-in-sudoers.patch
Patch freeipa-mkosek-446-sudoorder-missing-in-sudoers.patch sent for review
master: 48ffe39[[BR]] ipa-3-3: 66ac077
Metadata Update from @mkosek: - Issue assigned to mkosek - Issue set to the milestone: FreeIPA 3.3.x - 2014/01 (bug fixing)
Login to comment on this ticket.