There are a number of different runas options and it can be confusing to tell what is what.
One example is ipasudorunasgroup and ipasudorunas and setting a group.
I think in general the doc entry of the attributes should be revisited to see if they can be made more clear and in particular add some additional verbiage to the top-level command doc explaining how the attributes related to sudo.
attachment freeipa-jraquino-0039-Improve-sudorule-documentation.patch
If you want to be really pedantic, change "who's" to "whose" in the patch. Otherwise, everything looks good.
master: 1077343
ipa-2-1: eb804d4
Metadata Update from @rcritten: - Issue assigned to jraquino - Issue set to the milestone: FreeIPA 2.1.1 (bug fixing)
Login to comment on this ticket.