<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Account is locked at SAS Server in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414781#M11268</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello all,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thanks for the suggestions so far.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I think I might be onto the issue (at least in my case):&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Our sasauth.conf is configured as follows:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtries=5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesPeriod=60&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesWait=300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So there should be a maximum wait of 5 Minutes. However I have seen longer wait times. My best guess is that the wait time of 5 minutes (in this example) is prolonged or refreshed everytime the user tries to login within the 5 minutes of the maxtriesWait.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 4&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesWait set to 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt within the 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesWait set to 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt within the 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesWait set to 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;etc...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But then again this is just my guess. The maxtriesWait could also be accumulated for each unsuccessful login attempt while maxtriesWait is still active.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It would be good to know, how sasauth works when the maxtriesWait has been reached and another login attempt is made.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;The documentation (&lt;A href="http://support.sas.com/documentation/installcenter/en/ikfdtnunxcg/66380/PDF/default/config.pdf" target="_blank"&gt;Configuration Guide for SAS® 9.4 Foundation for UNIX Environments&lt;/A&gt;) might be more helpful with a few explaining lines. Or am I searching in the wrong place?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also it says that authentication might be&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sasauth =&amp;gt; Unix OS =&amp;gt; /etc/passwd&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sasauth =&amp;gt; /etc/passwd&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Our sasauth.conf says "method = pw". Does this mean we go through the Unix OS and then /etc/passwd or does this mean sasauth does the check versus /etc/passwd? This might be good to know in order to tighten the search, whether the OS might be involved at all in this process or if it a behaviour of sasauth.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Michael&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2017 09:10:34 GMT</pubDate>
    <dc:creator>mfab</dc:creator>
    <dc:date>2017-11-20T09:10:34Z</dc:date>
    <item>
      <title>AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/227928#M3440</link>
      <description>&lt;P&gt;I have a user who has been having his account locked out at the domain level and has happened numerous times since Friday. This user is high profile. This started on Friday and has been continuing for the last few days. I have my server and security teams working the issue with no results. The user gets his account unlocked and within the hour it is getting locked. The security monitor SPLUNK reports that my SAS server is the one locking him out. Over the last three days we have rebooted the server, deleted and re-added the account, and had him try to access production, backup and devel servers. Today we opened a SAS Track and are waiting for a response. Since this user supports higher management here, I used a "SERVICE" account that I had in reserve and logged him in as that from his PC through to the server. He has been stable all afternoon via that method. I, in turn is masquerading as the user to see if I while impersonating him get locked out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm runnning Office Analytics single machine 9.4 M2. The user is running EG 6.1 and I am running EG 7.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm open to any and all suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jerry Coppa SAS Admin at PA DHS&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 20:36:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/227928#M3440</guid>
      <dc:creator>DHS_SASADM</dc:creator>
      <dc:date>2015-09-30T20:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/227943#M3441</link>
      <description>&lt;P&gt;I had a problem very similar to this and it was caused by old&amp;nbsp;remote login sessions to our SAS server that were just disconnected but not signed out. In the meantime I had changed my password but the old sessions kept trying to authenticate and kept locking me out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does your user have remote login access? If not another possibility is having his old password stored in SAS metadata or in scheduled jobs. Use SAS Management Console to update the metadata-stored password or to re-schedule the jobs.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 20:58:57 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/227943#M3441</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2015-09-30T20:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/227966#M3442</link>
      <description>&lt;P&gt;Have seen this before also but can't recall the exact problem... &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I gather the user can't log onto the server directly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given you have rebooted the server etc, a rouge session doesn't seem to be the issue...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you have credentials stored in the metadata? or hardcoded in SAS code? &amp;nbsp;are there any SAS jobs running on the server when the account is locked? &amp;nbsp;Is it after they do something in SAS or is it even when they don't do anything?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although it is the SAS server that is seen to be be doing this it may not be SAS that is the issue....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Barry&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 23:01:11 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/227966#M3442</guid>
      <dc:creator>twocanbazza</dc:creator>
      <dc:date>2015-09-30T23:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/228141#M3445</link>
      <description>&lt;P&gt;There are a lot of possible causes.&lt;/P&gt;&lt;P&gt;- The existance of some user ghostprocesses still running and connecting at intervals&lt;/P&gt;&lt;P&gt;- The coding of the old/wrong password in a connection profile. (eguide amo/ .net&amp;nbsp;&amp;nbsp;&amp;nbsp; DI SMC /java)&lt;/P&gt;&lt;P&gt;- the caching (eg conncet) in a SAS metadatadata autentication location&lt;/P&gt;&lt;P&gt;- the usage&amp;nbsp;hard coded of user/password combination.&lt;BR /&gt;Finding and seeing these user errors can be hard.&lt;BR /&gt;&lt;BR /&gt;Than you can ahve problems in the SAS system itself.&lt;/P&gt;&lt;P&gt;- The login can be delayed&amp;nbsp;by failed logins. In those cases the metadata login can get delayed in a unusable way.&lt;/P&gt;&lt;P&gt;When the user does a login and wille retry&amp;nbsp;with different password&amp;nbsp;thinking it are typos it can cause a lock.&lt;BR /&gt;- After changing the password the sasauthentication can be delayed separtely&amp;nbsp; of your OS setttings.&lt;/P&gt;&lt;P&gt;Getting a new password after an unlock can cause the marvelous sitaution you can loging at the OS level but using SAS for that will fail. After several retries it can get locked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 21:54:46 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/228141#M3445</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2015-10-01T21:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414330#M11228</link>
      <description>&lt;P&gt;Hello &lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/9411"&gt;@jakarman&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have stumbled upon a problem that might be related to what you were mentioning.&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;the caching (eg conncet) in a SAS metadatadata autentication location&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;After changing the password the sasauthentication can be delayed separtely&amp;nbsp; of your OS setttings&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Situation is as follows:&lt;/P&gt;
&lt;P&gt;Host is unix and the password is changed.&lt;/P&gt;
&lt;P&gt;User tries to login from EG/WebReportStudio/Excel Add-In.&lt;/P&gt;
&lt;P&gt;User receives promt to enter valid username and password&lt;/P&gt;
&lt;P&gt;User enters new information.&lt;/P&gt;
&lt;P&gt;SAS says that the information is still invalid.&lt;/P&gt;
&lt;P&gt;I then deleted the user account, created it as new account - still no success.&lt;/P&gt;
&lt;P&gt;After a while (15-30 minutes) the login suddenly works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been trying to figure out if any setting in the omaconfig.xml (&lt;A href="http://documentation.sas.com/?docsetId=bisag&amp;amp;docsetTarget=n070fn7r6yuz53n19c7l80f3hr1g.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=de" target="_blank"&gt;hints&lt;/A&gt;) could have had any effect, but no clue was found.&lt;/P&gt;
&lt;P&gt;After 3 unsuccessful attempts, the account should have been "locked", but what does this mean? How long is it locked and why did it suddenly work out?&lt;/P&gt;
&lt;P&gt;Also, where would the metadata-server or connect spawner (?) cache any information? Are there any hints to how frequently cashing will take place?&lt;/P&gt;
&lt;P&gt;Also log files did not provide any useful information aside from the fact, that the user login was denied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for any hints and suggestions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 10:57:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414330#M11228</guid>
      <dc:creator>mfab</dc:creator>
      <dc:date>2017-11-17T10:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414342#M11230</link>
      <description>&lt;P&gt;This is something that I have noticed repeatedly. Once the metadata server has received a "failed" message from the OS for an authentication attempt, it takes some time before it re-checks the authentication.&lt;/P&gt;
&lt;P&gt;eg&lt;/P&gt;
&lt;P&gt;- user attempts connection, is rejected because password is expired in OS&lt;/P&gt;
&lt;P&gt;- user logs in via ssh, changes password as required&lt;/P&gt;
&lt;P&gt;- user tries with new password, but is rejected; metadata log reports "Access denied"&lt;/P&gt;
&lt;P&gt;- user waits a given amount of time and tries again - voila, works&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 11:42:04 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414342#M11230</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-11-17T11:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414345#M11231</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/6453"&gt;@mfab&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is a behaviour quite old ( I know it since back 9.1.3 ) and it remains the same, with some improvements, now it happens less often.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;General solution is to refresh the SAS Application Server, or even the Object Spawner.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have a Grid environment, this might happen on the LSF level as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 12:29:53 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414345#M11231</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2017-11-17T12:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414350#M11232</link>
      <description>&lt;P&gt;Thanks for the answers so far!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/11562"&gt;@Kurt_Bremser&lt;/a&gt;: do you see any chance, that SAS will document the default behaviour anywhere? It would be pleasant to at least know how the system works, even if there is no chance in changing things. Would you open a support ticket for this or does anyone from SAS have a look into the communities from time to time?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/35204"&gt;@JuanS_OCS&lt;/a&gt;: what do you mean by "refresh" - are you thinking of restart? This would not be applicable for our purposes.&lt;/P&gt;
&lt;P&gt;We want to prevent user logins by using the "passwd --lock &amp;lt;username&amp;gt;" command in Cronjobs. So users can't login during given times. We would not want to restart any services because some users did try to login and have their login in SAS ... ahm ... let's say deactivated or not refreshed.&lt;/P&gt;
&lt;P&gt;A solution from within SAS to deactivate accounts or prevent login at certain times would also be desirable, but there does not seem to be any option like this (and I wonder why, since the rest of the metadata management in SAS is quite nice).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 12:47:49 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414350#M11232</guid>
      <dc:creator>mfab</dc:creator>
      <dc:date>2017-11-17T12:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414354#M11233</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/6453"&gt;@mfab&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I support authentication on UNIX/Linux.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you guys talking about PAM or Host authentication?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/11562"&gt;@Kurt_Bremser&lt;/a&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;user tries with new password, but is rejected; metadata log reports "Access denied"&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please enable &lt;A href="http://support.sas.com/kb/39/891.html" target="_self"&gt;sasauth-debug&lt;/A&gt;. Repeat the problem and show me:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The metadata server log&lt;/LI&gt;
&lt;LI&gt;sasauth-debug log&lt;/LI&gt;
&lt;LI&gt;An output from this command (must be started as root): grep sasauth /var/log/secure&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 17 Nov 2017 13:48:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414354#M11233</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-11-17T13:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414361#M11235</link>
      <description>&lt;P&gt;Hi &lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;. It's not really a problem, as it can be solved by just giving the metadata server time to "drop the cache", or whatever it is.&lt;/P&gt;
&lt;P&gt;I just had a case right now, where a user changed the password after failing to log in to the metadata server (because of password expiration), and could not log in to the metadata server for about half an hour. Then the EG connection profile sudddenly worked (with the already entered new password) without asking for credentials again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using host authentication on AIX, the phenomenon has been there since at least 9.2 on AIX 5.3, and it persists with 9.4 TS1M2 on AIX 7.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can find no sasauth-debug in my !SASROOT/utilities/bin&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 13:22:05 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414361#M11235</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-11-17T13:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414364#M11236</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/11562"&gt;@Kurt_Bremser&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SAS relies on the underlying operating system and APIs to handle authentication request, so most likely the cache was somewhere on the system. Without an additional debug I cannot help. If you wish, open a track and ask to assign it to me, I'm sure we will find the root cause.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 13:31:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414364#M11236</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-11-17T13:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414366#M11237</link>
      <description>&lt;P&gt;Is KB&lt;/P&gt;
&lt;H2&gt;&lt;I&gt;15231&lt;/I&gt;&lt;/H2&gt;
&lt;P&gt;really the one that you wanted to direct me to? It's the one that deals with the necessary setuid bits, but that is surely not a problem here.&lt;/P&gt;
&lt;P&gt;I think you meant &lt;A href="http://support.sas.com/kb/39/891.html" target="_blank"&gt;http://support.sas.com/kb/39/891.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I have enabled the logging, will try if I can glean something from the logs if the effect happens again.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 13:45:22 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414366#M11237</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-11-17T13:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414368#M11238</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/11562"&gt;@Kurt_Bremser&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are right, sorry about that, I've copied the wrong link &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 13:47:26 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414368#M11238</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-11-17T13:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414394#M11239</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/11562"&gt;@Kurt_Bremser&lt;/a&gt;: I really appreciate all your effort! I hope, you will track this thing down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can add, that we use Host authentication as well (SLES11.4 / SAS9.4M1).&lt;/P&gt;
&lt;P&gt;Unfortunately I cannot enable sasauth-debug as of now and as quickly as Kurt.&lt;/P&gt;
&lt;P&gt;Our timeline was roughly as follows:&lt;/P&gt;
&lt;P&gt;t0 - "passwd --lock ..." on commandline&lt;/P&gt;
&lt;P&gt;t1 - first login attempt: not possible (as expected)&lt;/P&gt;
&lt;P&gt;t5 - "passwd --unlock ..." on commandline&lt;/P&gt;
&lt;P&gt;t6 - login attempt: not possible (not as expected)&lt;/P&gt;
&lt;P&gt;t7 - login via SSH: possible (as expected)&lt;/P&gt;
&lt;P&gt;t8 - setting user passwort in credentials via Management Console + login attempt: no effect&lt;/P&gt;
&lt;P&gt;t11 - removing user login credentials in Management Console + login attempt: no effect&lt;/P&gt;
&lt;P&gt;t12 - removed user completely in Management Console, added user again + login attempt: no effect&lt;/P&gt;
&lt;P&gt;t30 - randomly tried another login attempt: possible&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I would also think that there might be some sort of caching on the host side. Especially since I removed the login credentials and even removed and added the complete user (I would strongly hope that a new user has his credentials checked against the host, not against some cache).&lt;/P&gt;
&lt;P&gt;However, I am wondering that SSH-Login was working properly way earlier than via SAS Metadata.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 14:28:21 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414394#M11239</guid>
      <dc:creator>mfab</dc:creator>
      <dc:date>2017-11-17T14:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414396#M11240</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/6453"&gt;@mfab&lt;/a&gt;,&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I can add, that we use Host authentication as well (SLES11.4 / SAS9.4M1).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am wondering that SSH-Login was working properly way earlier than via SAS Metadata.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSHD uses PAM for the authentication. You can also switch SAS to use PAM for the authentication, even for local users:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/kb/49/432.html" target="_self"&gt;http://support.sas.com/kb/49/432.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 14:41:54 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414396#M11240</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-11-17T14:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414589#M11258</link>
      <description>&lt;P&gt;Michael, with the omaconfig you have reviewed the internal account definitions &lt;BR /&gt;With that you can validate passwords against LDAP/Kerberos/AD but there is no immediate connection to the OS security itself.&lt;/P&gt;
&lt;P&gt;It is a kind of working in ignoring security at het data/os-level and combine those to a shared grouped&amp;nbsp;account that is maintained and owned by SAS. I hope SAS institute is not responsible or if they are. Anyway that way of working should be described well as losing auditablity traceablity by normal tools for that.&amp;nbsp;--- high profile user, hurts ----&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For unix security technical way of working, there are many options:&lt;BR /&gt;&lt;A href="http://support.sas.com/documentation/installcenter/en/ikfdtnunxcg/66380/PDF/default/config.pdf" target="_blank"&gt;http://support.sas.com/documentation/installcenter/en/ikfdtnunxcg/66380/PDF/default/config.pdf&lt;/A&gt; review PAM / sasauth.&lt;BR /&gt;Getting into LDAP/AD depending on the size of the company there can be many LDAP/AD servers.&lt;BR /&gt;Updating the password in a windows environment and expecting it immediately active can be frustrating. At windows you get the immediate response&amp;nbsp;of the update password as you are being&amp;nbsp;connected&amp;nbsp;to that one.&lt;BR /&gt;&lt;A href="https://blogs.technet.microsoft.com/kenstcyr/2008/07/05/understanding-urgent-replication/&amp;nbsp;&amp;nbsp;" target="_blank"&gt;https://blogs.technet.microsoft.com/kenstcyr/2008/07/05/understanding-urgent-replication/&amp;nbsp;&amp;nbsp;&lt;/A&gt; Normally it should be implemented well but you never know.&lt;BR /&gt;&lt;BR /&gt;There is an other weird behavior of the sasauth module. It is that module checking the password while runnig at root-level.&lt;BR /&gt;What will happen when validating a user/password&amp;nbsp; combination when there are delays/lock wait policies&amp;nbsp;being activated at the AD origin. Will the user account behave als normal Windows or will there happen something different?&lt;BR /&gt;The latter having seen happening. Trying a locked out user several times and the delay time went ever up never being reset by a correct login. You must be very patient and confident to see the login happening after an hour or so.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Nov 2017 20:07:26 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414589#M11258</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2017-11-18T20:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414781#M11268</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello all,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thanks for the suggestions so far.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I think I might be onto the issue (at least in my case):&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Our sasauth.conf is configured as follows:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtries=5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesPeriod=60&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesWait=300&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So there should be a maximum wait of 5 Minutes. However I have seen longer wait times. My best guess is that the wait time of 5 minutes (in this example) is prolonged or refreshed everytime the user tries to login within the 5 minutes of the maxtriesWait.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 4&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt 5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesWait set to 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt within the 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesWait set to 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;login attempt within the 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;maxtriesWait set to 5 minutes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;etc...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But then again this is just my guess. The maxtriesWait could also be accumulated for each unsuccessful login attempt while maxtriesWait is still active.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It would be good to know, how sasauth works when the maxtriesWait has been reached and another login attempt is made.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;The documentation (&lt;A href="http://support.sas.com/documentation/installcenter/en/ikfdtnunxcg/66380/PDF/default/config.pdf" target="_blank"&gt;Configuration Guide for SAS® 9.4 Foundation for UNIX Environments&lt;/A&gt;) might be more helpful with a few explaining lines. Or am I searching in the wrong place?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also it says that authentication might be&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sasauth =&amp;gt; Unix OS =&amp;gt; /etc/passwd&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sasauth =&amp;gt; /etc/passwd&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Our sasauth.conf says "method = pw". Does this mean we go through the Unix OS and then /etc/passwd or does this mean sasauth does the check versus /etc/passwd? This might be good to know in order to tighten the search, whether the OS might be involved at all in this process or if it a behaviour of sasauth.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Michael&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 09:10:34 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414781#M11268</guid>
      <dc:creator>mfab</dc:creator>
      <dc:date>2017-11-20T09:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414956#M11275</link>
      <description>&lt;P&gt;Michael, yep that is the terrible thing we struggled quite a lot&amp;nbsp;on that.&lt;BR /&gt;The updates time-outs on the OS and the SAS were done seperately not aligned to each other.&lt;/P&gt;
&lt;P&gt;The pw checking was calling the OS and the OS being redirected to LDAP (AD) for only normal users as service accounts being local.&lt;BR /&gt;&lt;BR /&gt;When this is also you case testing / validating will get more easy. Have at least two accounts availiable.&lt;BR /&gt;One being getting locked and at every attempt increasing the time (accumulating). The other as normal user just logging in an measuring the time in responding for normal usage.&lt;BR /&gt;Having a test for infra validation of a sas installation available you can try those settings in the sasauth.conf on that scenario changing values and just replay&amp;nbsp;the user-locking and changing passwords.&amp;nbsp;That environment should be very similar to the real one. A stand alone one on a desktop will not do that job.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 21:18:56 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/414956#M11275</guid>
      <dc:creator>jakarman</dc:creator>
      <dc:date>2017-11-20T21:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/488390#M13973</link>
      <description>&lt;P&gt;I had the SAS server locking my AD account repeatedly. It was tracked it back to when I tested the SAS studio installation after which I had then changed my password. I did not logon to SAS studio again. The password was changed in the my profile from within SAS EG but somehow SAS would still pick up my old password stored by SAS studio run that against the SAS server and lock my AD account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Removing the password from the SAS studio saved information worked for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 23:41:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/488390#M13973</guid>
      <dc:creator>NZ_Hockey_Mum</dc:creator>
      <dc:date>2018-08-20T23:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: AD Account is locked at SAS Server</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/494825#M14255</link>
      <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/222603"&gt;@NZ_Hockey_Mum&lt;/a&gt;&amp;nbsp;! Hope it can help many&amp;nbsp;others.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Sep 2018 13:14:09 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/AD-Account-is-locked-at-SAS-Server/m-p/494825#M14255</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2018-09-12T13:14:09Z</dc:date>
    </item>
  </channel>
</rss>

