Salesforce

KB-2434: Enabling sudo for users on a smart-card-only machine.

« Go Back

Information

 
TitleKB-2434: Enabling sudo for users on a smart-card-only machine.
URL NameKB-2434-Enabling-sudo-for-users-on-a-smart-card-only-machine
Knowledge Article TypeHow To’s
Article TypeKnowledge
ArticleType 
ProductMac Management
ComponentSmartCard Support
Version 
Tags
Internal Comments
Article Edits
Bug #27676
Solution ID2434
Knowledge Base Article Details
Question:

Is it possible to enable sudo for users on a smart-card-only machine?


Answer: 

Yes. For machines that are solely smart-card-required - the only way to do this is to set the "nopasswd" flag for specified users.
  • When the per-user "Smart card required to log in" setting is checked in ADUC (as opposed to the per-machine GP setting), the user's password is deleted from Active Directory, so no password exists to be entered.
  • The ‘passwd’ flag in sudoers is set to prevent users from leaving their workstation and then another person coming and using sudo on the system.
     
  • With smart cards, the ideal situation is whenever the user leaves the workstation; they will also take the smartcard with them (this event can be set to auto-lock the system via group policy).

See also:
Created ByArticle Admin
Solution CreatorBrian Lau
DraftNot Checked
LithiumId
Lithium_Board_Id
Lithium_View_Href
Tags 
Category 
ArticleImage
Known IssuesNot Checked

Powered by