Cloned from https://bugzilla.redhat.com/show_bug.cgi?id=1697951
Description of problem: After migration from winsync agreement to trust using ipa-winsync-migrate tool, wrapper groups are created to preserve membership of users in groups, hbac rules, selinuxusermaps and roles. For some reason sudorules are not preserved, though they are mentioned in [1] and [2]. Adding preserving of sudorules will make behavior of ipa-winsync-migrate more consistent. Alternatively a documentation could be updated to clearly state that sudorules are not preserved.
Additional info:
Related commit: [3].
[1] https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/windows_integration_guide/migrate-sync-trust [2] https://pagure.io/freeipa/issue/4943 [3] https://pagure.io/freeipa/c/8d30feb5391026a42a2f8da5df8d539311963b86
Login to comment on this ticket.