On Thu, 17 Apr 2014 12:44:57 +0200 "Michael Ströder"
<michael(a)stroeder.com>
wrote
I can see substring filters like this in my LDAP logs:
[..] (|(sudoHost=*\5C*)(sudoHost=*?*)(sudoHost=*\2A*)(sudoHost=*[*]*))))
(stripped the lenghty filter)
Is this sssd asking for sudoRole entries?
Hmm, clarified with the sysadmin to use:
ldap_sudo_use_host_filter = false
IMHO this should be the default because substring searches like above are
really stupid.
Ciao, Michael.