What is the relationship between sewhoami and sesu?
search cancel

What is the relationship between sewhoami and sesu?

book

Article ID: 448251

calendar_today

Updated On:

Products

CA Privileged Access Manager - Server Control (PAMSC)

Issue/Introduction

On occasion the sewhoami -a command shows the user as an OS_user or root but does not list the expected AD group names in the Group Name table. When this happens the sesu command fails when attempting to switch to another user account.

Cause

PAMSC policies can be applied directly to a user but most often they are applied to a user group. This group can be based on local OS groups or  AD groups when an Active Directory integration is implemented in the Linux or Unix OS. The sewhoami command is useful when trying to evaluate why a policy, including sesu policies, is not being allowed. If a user is misidentified or their user groups are not identified properly, the policy cannot be properly applied.

Resolution

The relationship between sewhoami and the policies that are applied is simply that the sewhoami can show you the details of what PAMSC has identified as the current logged in user. In oder to ensure any policy is applied you can use the sewhoami command to validate and fix any underlying identification issues.