https://bugzilla.redhat.com/show_bug.cgi?id=1885874
--- Comment #5 from Pavel Březina pbrezina@redhat.com --- To be clear: you kept the rule in the IPA server, you destroyed, re-created and re-enrolled the host (where sudo runs) and this fixed the issue? So you did not changed the sudo rule?