To take the policy from one server and apply it to the other, 'checkout' the policy from the original, then copy it somewhere accessible from the new server, and then 'commit' it there.
1. Checkout the policy so you can make a copy.
On the PMpolicy server directly, you can use the /opt/quest/sbin/pmpolicy command to check out the policy (so you can make a copy) and check it back in again.
First command checks it out into the /tmp folder.
The file will be here; /tmp/policy_sudo/sudoers
On the server you wish to copy the policy from, run:
/opt/quest/sbin/pmpolicy checkout -d /tmp
Example output:
# /opt/quest/sbin/pmpolicy checkout -d /tmp
** Validate options [ OK ]
** Checkout to /tmp/policy_sudo
** Create directory [ OK ]
** Check out working copy [ OK ]
** Checked out revision:8
** Copy files [ OK ]
** Perform syntax check [ OK ]
2. Copy the file so you can use the copy to apply on the new server.
Now, copy the file so you have it elsewhere, then commit the policy (check it back in) with the following command:
/opt/quest/sbin/pmpolicy commit -d /tmp
Example output:
# /opt/quest/sbin/pmpolicy commit -d /tmp
** Validate options [ OK ]
** Commit copy in directory:/tmp/policy_sudo
** Check directory [ OK ]
** Perform syntax check [ OK ]
** Verify files to commit [ OK ]
3. Checkout the policy on the new server using the same steps from above, then adjust the file as required with the content from the original server, and then commit it back in as above.