Feature: enviroment variables $HOSTNAME usable in GPOs #1037
Labels
enhancement
New feature or request
good first issue
Good for newcomers
help wanted
Extra attention is needed
Is there an existing request for this feature?
Describe the feature
Our company is aiming to restrict the sudoer privilege very strict and for each computer individually.
Therefore for windows we have stared to create goups for this purpose e.g. secLoaclAdmin-DEVMACHINE01
In the Windows policies we are able to substitute the Hostname with a env variable %COMPUTERNAME% and thus in turn applies the correct group to the machines.
Unfortunately the adsys policy Ubuntu > Client management > Privilege Authorization > Client administrators is not honoring $HOSTNAME and only writes this as text into the file /etc/polkit-1/localauthority.conf.d/99-adsys-privilege-enforcement.conf
Describe the ideal solution
Ideally this adsys policy would start to accept $HOSTNAME as a variable and processes this accordingly on the machine
Alternatives and current workarounds
we are creating a seperate GPO per machine which is leading to very cluttered GPO mgmt
Ubuntu users: System information
No response
Non Ubuntu users: System information
Additional information
No response
Double check your logs
The text was updated successfully, but these errors were encountered: