Bugzilla – Bug 151
Request for fallback capability within LDAP support
Last modified: 2008-01-06 11:57:47 MST
Per a recent email exchange with Aaron Spangler, who asked me to enter this faintly feature-request-ish bug; I'd assign it to him if I knew the account he is in bugzilla under... In the event of LDAP being inaccessible for whatever reason, there would be value in having some form of backup capability within sudo - a timeout, perhaps - after which sudo may look for a local sudoers file and use that. Of course, if the code to make it work with nsswitch.conf were in place, then perhaps that would work as well (e.g. "sudo: ldap files" in nsswitch.conf) though the failover might not be what is desired by all... it probably needs to be optional behavior, at least as a compile time option if not a run time configuration option, as someone is bound to object one way or the other...
Reassigning to me. Will be resolved once the nsswitch.conf support is up to snuff.
nsswitch.conf support is present in sudo 1.7b1, released today. Additionally, multiple LDAP servers can be specified along with a connection timeout.