summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJakub Hrozek <jhrozek@redhat.com>2014-10-17 18:14:45 +0200
committerJakub Hrozek <jhrozek@redhat.com>2014-10-22 15:44:51 +0200
commit3f9e2c24dbc14b2eafbe4f5a5ee16fe9af3c3f75 (patch)
tree2da39c06edb91e2ec84396c8806284fc1c9e46f8
parent22f4bcbb211bf800af647ad1fc9595a8020a6fe6 (diff)
downloadsssd-3f9e2c24dbc14b2eafbe4f5a5ee16fe9af3c3f75.tar.gz
sssd-3f9e2c24dbc14b2eafbe4f5a5ee16fe9af3c3f75.tar.xz
sssd-3f9e2c24dbc14b2eafbe4f5a5ee16fe9af3c3f75.zip
SUDO: Run the sudo responder as the SSSD user
Reviewed-by: Pavel Reichl <preichl@redhat.com> Reviewed-by: Simo Sorce <simo@redhat.com>
-rw-r--r--src/monitor/monitor.c3
-rw-r--r--src/responder/sudo/sudosrv.c2
2 files changed, 3 insertions, 2 deletions
diff --git a/src/monitor/monitor.c b/src/monitor/monitor.c
index 61a9f0b84..d09aeba90 100644
--- a/src/monitor/monitor.c
+++ b/src/monitor/monitor.c
@@ -1065,7 +1065,8 @@ static bool svc_supported_as_nonroot(const char *svc_name)
if ((strcmp(svc_name, "nss") == 0)
|| (strcmp(svc_name, "pam") == 0)
|| (strcmp(svc_name, "autofs") == 0)
- || (strcmp(svc_name, "pac") == 0)) {
+ || (strcmp(svc_name, "pac") == 0)
+ || (strcmp(svc_name, "sudo") == 0)) {
return true;
}
return false;
diff --git a/src/responder/sudo/sudosrv.c b/src/responder/sudo/sudosrv.c
index 038e3fd7d..a25f98eca 100644
--- a/src/responder/sudo/sudosrv.c
+++ b/src/responder/sudo/sudosrv.c
@@ -195,7 +195,7 @@ int main(int argc, const char *argv[])
/* set up things like debug, signals, daemonization, etc... */
debug_log_file = "sssd_sudo";
- ret = server_setup("sssd[sudo]", 0, 0, 0, CONFDB_SUDO_CONF_ENTRY,
+ ret = server_setup("sssd[sudo]", 0, uid, gid, CONFDB_SUDO_CONF_ENTRY,
&main_ctx);
if (ret != EOK) {
return 2;