<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAS 9.4M2 BI Platform with IWA/Kerberos in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405487#M10741</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a Clustered Metadata server (3 x Win 2012 R2 VMs) and 2 Compute servers which are Load Balanced.&lt;/P&gt;
&lt;P&gt;We want to switch from user login to sso using IWA/Kerberos.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In doing so we discovered that one of our Compute Servers are missing SPNs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question: We can manually create the required SPNs, but which SAS Service account is best used for the SPN?&lt;/P&gt;
&lt;P&gt;SASINST, SASSRV or SASADM?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And then does it have to be the same service account used for ALL the SPNs on each server. The&amp;nbsp;installers cannot remember how the original SPNs were set up during the initial installation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2017 12:04:20 GMT</pubDate>
    <dc:creator>Lenvdb</dc:creator>
    <dc:date>2017-10-19T12:04:20Z</dc:date>
    <item>
      <title>SAS 9.4M2 BI Platform with IWA/Kerberos</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405487#M10741</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a Clustered Metadata server (3 x Win 2012 R2 VMs) and 2 Compute servers which are Load Balanced.&lt;/P&gt;
&lt;P&gt;We want to switch from user login to sso using IWA/Kerberos.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In doing so we discovered that one of our Compute Servers are missing SPNs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question: We can manually create the required SPNs, but which SAS Service account is best used for the SPN?&lt;/P&gt;
&lt;P&gt;SASINST, SASSRV or SASADM?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And then does it have to be the same service account used for ALL the SPNs on each server. The&amp;nbsp;installers cannot remember how the original SPNs were set up during the initial installation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 12:04:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405487#M10741</guid>
      <dc:creator>Lenvdb</dc:creator>
      <dc:date>2017-10-19T12:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4M2 BI Platform with IWA/Kerberos</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405501#M10742</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41119"&gt;@Lenvdb&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="http://go.documentation.sas.com/?docsetId=bisecag&amp;amp;docsetTarget=n1d1zo1jsf2o0en1ehu4c4simfky.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en" target="_self"&gt;How to Configure Integrated Windows Authentication&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;If the metadata server is clustered and runs on Windows, or if your SAS servers are configured using DNS aliases, manually register SPNs. &lt;A href="http://go.documentation.sas.com/?docsetId=bisecag&amp;amp;docsetTarget=n1d1zo1jsf2o0en1ehu4c4simfky.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en#p0gc8vjx9d94xgn1ngjgr07vhfvo" target="_self"&gt;See Manual Registration&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Manually Registering Object Spawner SPNs&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When using a service level account to run the object spawner service in a SAS Grid environment, you need to configure the default SPNs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE class=" language-sas"&gt;setspn –A SAS/computerNetbios –u &lt;STRONG&gt;domain\ObjectSpawnerServiceAccount&lt;/STRONG&gt;
setspn –A SAS/computerFullname –u &lt;STRONG&gt;domain\ObjectSpawnerServiceAccount
&lt;/STRONG&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;In non-grid environments, you can configure custom SPNs, such as the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE class=" language-sas"&gt;setspn –A SASWS/computerNetbios –u &lt;STRONG&gt;domain\ObjectSpawnerServiceAccount&lt;/STRONG&gt;
setspn –A SASWS/computerShortname –u &lt;STRONG&gt;domain\ObjectSpawnerServiceAccount&lt;/STRONG&gt;&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 19 Oct 2017 12:35:31 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405501#M10742</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-10-19T12:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4M2 BI Platform with IWA/Kerberos</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405504#M10743</link>
      <description>&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you for this. Yes - I saw these instructions. My problem is I am new to this organisation and I was not there when it was installed on the original server, so I have no idea what the correct service account to use would be: SASINST? SASSRV? What I am really asking is if someone here has done this before, which account is recommended? I will most likely need to go and delete/recreate the SPNs previously set up, and document this so they know what I did to install IWA.  We do not use Grid. Yet our 1st Compute node was set up as SAS/SASServ1 and not SASWS/SASServ1.&lt;BR /&gt;&lt;BR /&gt;Thank you for your reply.&lt;BR /&gt;Much appreciated.</description>
      <pubDate>Thu, 19 Oct 2017 12:44:23 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405504#M10743</guid>
      <dc:creator>Lenvdb</dc:creator>
      <dc:date>2017-10-19T12:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4M2 BI Platform with IWA/Kerberos</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405511#M10745</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41119"&gt;@Lenvdb&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The object spawner is up and running now? Who started it? Most likely SASINST will be the service account. SASSRV is the account that is used for SAS Token Authentication.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 13:01:01 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405511#M10745</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-10-19T13:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4M2 BI Platform with IWA/Kerberos</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405517#M10746</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again for your reply...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would assume that it is the SASINST account, as it is used for about everything else.&lt;/P&gt;
&lt;P&gt;I had a look at the Object Spawners and they seem to run under a Local System Account&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 388px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/16005iA7DDF206F53D0504/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 13:08:52 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/405517#M10746</guid>
      <dc:creator>Lenvdb</dc:creator>
      <dc:date>2017-10-19T13:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4M2 BI Platform with IWA/Kerberos</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/407575#M10903</link>
      <description>&lt;P&gt;We have now set up some SPN's on the Compute node which had these missing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a number of users complaining about not getting access to our SAS Metadata using IWA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 3 Metadata Nodes in our cluster:&lt;/P&gt;
&lt;P&gt;VM1&lt;/P&gt;
&lt;P&gt;VM2 (Master)&lt;/P&gt;
&lt;P&gt;VM3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Node VM1 we regularly get these errors in the Log:&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#993366"&gt;2017-10-26T08:33:00,805 INFO [09550903] :sasinst@xxxxxxxxxxxxxx - Client connection 26275365 for user sasevs@saspw closed.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;2017-10-26T08:33:01,805 INFO [09550910] :sasinst@xxxxxxxx - Unexpected error in function AcceptSecurityContext. Error -2146893048 (The token supplied to the function is invalid ).&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;2017-10-26T08:33:01,805 WARN [09550910] :sasinst@xxxxxxxxx - New client connection (26274325) rejected from server port 8561 for unknown IWA user. Peer IP address and port are [::ffff:10.200.4.96]:63063 for APPNAME=SAS Enterprise Guide.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;2017-10-26T08:33:01,805 INFO [09550910] :sasinst@xxxxxxxxxx - Client connection 26274325 closed.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;2017-10-26T08:33:01,805 INFO [09418531] :sasinst@xxxxxxxxx - Unexpected error in function AcceptSecurityContext. Error -2146893048 (The token supplied to the function is invalid ).&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;2017-10-26T08:33:01,805 WARN [09418531] :sasinst@xxxxxxxx - New client connection (26273718) rejected from server port 8561 for &lt;U&gt;&lt;STRONG&gt;unknown IWA user&lt;/STRONG&gt;&lt;/U&gt;. Peer IP address and port are [::ffff:10.200.4.96]:63062 for APPNAME=SAS Enterprise Guide.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;2017-10-26T08:33:01,805 INFO [09418531] :sasinst@xxxxxxxxxxxxx - Client connection 26273718 closed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These errors do not appear on VM2 or VM3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What could be the cause for this?&lt;/P&gt;
&lt;P&gt;How do we fix it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also saw this error in our Event Log on VM1:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Activation context generation failed for "c:\program files\SASHome\sasdeploymentmanager\9.4\products\cfgwizard__94260__prt__xx__sp0__1\utilities\w64\sasshortcutmgr.exe". Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="ia64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762" could not be found. Please use sxstrace.exe for detailed diagnosis.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 09:02:05 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/407575#M10903</guid>
      <dc:creator>Lenvdb</dc:creator>
      <dc:date>2017-10-26T09:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4M2 BI Platform with IWA/Kerberos</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/407605#M10906</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41119"&gt;@Lenvdb&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have to pay attention to this message in your log:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;2017-10-26T08:33:01,805 INFO [09418531] :sasinst@xxxxxxxxx - Unexpected error in function AcceptSecurityContext. Error -2146893048 (The token supplied to the function is invalid ).&lt;BR /&gt;What could be the cause for this?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Most likely there was a problem with TCP communication, for an example with DNS server. Are you sure you have no messages such this in the event viewer?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;A socket operation was attempted to an unreachable host.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 11:14:07 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/407605#M10906</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-10-26T11:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4M2 BI Platform with IWA/Kerberos</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/407609#M10907</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Alex&lt;/P&gt;
&lt;P&gt;Sorry if I was unclear - this WAS the log entry in the event viewer in Windows.&lt;/P&gt;
&lt;P&gt;But it only happens on VM1 using IWA, not on VM2 or VM3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The System Event Viewer shows :&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The Security System has received an authentication request that could not be decoded. The request has failed.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the same time a Log was recorded in SAS Metadata:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF6600"&gt;2017-10-26T11:37:00,385 INFO [09785175] 26273237:sasinst@xxxxxxxxxxxxxL - Client connection 26273237 for user XSSEXEC@xxxxxxxxxxxxxxxxx closed.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;2017-10-26T11:37:06,621 INFO [09785027] :sasinst@xxxxxxxxxxxxxxxxxxxxx - Unexpected error in function AcceptSecurityContext. Error -2146893048 (The token supplied to the function is invalid ).&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;2017-10-26T11:37:06,621 WARN [09785027] :sasinst@xxxxxxxxxxxxxxxxxxxxx - New client connection (26276397) rejected from server port 8561 for unknown IWA user. Peer IP address and port are [::ffff:10.200.2.22]:61955 for APPNAME=SAS Enterprise Guide.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;2017-10-26T11:37:06,621 INFO [09785027] :sasinst@xxxxxxxxxxxx - Client connection 26276397 closed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 11:26:33 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/407609#M10907</guid>
      <dc:creator>Lenvdb</dc:creator>
      <dc:date>2017-10-26T11:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4M2 BI Platform with IWA/Kerberos</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/407616#M10909</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41119"&gt;@Lenvdb&lt;/a&gt;,&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;The Security System has received an authentication request that could not be decoded. The request has failed.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I suggest contacting Microsoft Technical Support about this problem.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 12:03:07 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4M2-BI-Platform-with-IWA-Kerberos/m-p/407616#M10909</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-10-26T12:03:07Z</dc:date>
    </item>
  </channel>
</rss>

