<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP / AD authentication in SAS Viya 3.2 - Full deployment in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417457#M11412</link>
    <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/35204"&gt;@JuanS_OCS&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can help with PAM authentication.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;How to set up the SAS-internal PAM configuration files?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://go.documentation.sas.com/?cdcId=calcdc&amp;amp;cdcVersion=3.2&amp;amp;docsetId=calauthmdl&amp;amp;docsetTarget=n1pkgyrtk8bp4zn1d0v1ln4869og.htm&amp;amp;locale=en#" target="_self"&gt;SAS Viya 3.2 Administration / Authentication: How To Configure PAM&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Nov 2017 16:04:26 GMT</pubDate>
    <dc:creator>alexal</dc:creator>
    <dc:date>2017-11-30T16:04:26Z</dc:date>
    <item>
      <title>LDAP / AD authentication in SAS Viya 3.2 - Full deployment</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417382#M11401</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a couple of questions, regarding authentication with Viya, when you select the full deployment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The OAuth authentication set up for the visual interfaces, speaking more specifically, I am talking about the Environment Manager, allows you to sync with a CN or an OU, for users and for the groups.
&lt;OL&gt;
&lt;LI&gt;If done on the groups, it gets the groups on that OU or CN&lt;/LI&gt;
&lt;LI&gt;If done on the users, it gets the direct users on the OU or CN.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; But apparently it is not getting the sub trees, hence, if there are Interactive accounts and System accounts (such as 'cas'), on different CNs or OUs (as they generally are/should be) .. is there any way to tell the Environment Manager to do so?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The authentication is happening OK in the Visual Environments (VA and EVM) but not in SAS Studio.
&lt;UL&gt;
&lt;LI&gt;I can log locally to the server with an AD / LDAP account&lt;/LI&gt;
&lt;LI&gt;I guess, I need to set up the SAS-internal PAM config files for cas and sasstudio&lt;/LI&gt;
&lt;LI&gt;How to set up the SAS-internal PAM configuration files?&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Any guidance or pin-pointing to the right direction would be welcome! Many thanks in advance,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Juan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 12:11:27 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417382#M11401</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2017-11-30T12:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP / AD authentication in SAS Viya 3.2 - Full deployment</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417457#M11412</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/35204"&gt;@JuanS_OCS&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can help with PAM authentication.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;How to set up the SAS-internal PAM configuration files?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://go.documentation.sas.com/?cdcId=calcdc&amp;amp;cdcVersion=3.2&amp;amp;docsetId=calauthmdl&amp;amp;docsetTarget=n1pkgyrtk8bp4zn1d0v1ln4869og.htm&amp;amp;locale=en#" target="_self"&gt;SAS Viya 3.2 Administration / Authentication: How To Configure PAM&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 16:04:26 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417457#M11412</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-11-30T16:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP / AD authentication in SAS Viya 3.2 - Full deployment</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417462#M11413</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;many thanks, however, I already have gone through it and that link just states the obvious, I am afraid. I mentioned the 2 PAM files, and the link pin-points to the same 2 PAM files:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;./etc/pam.d/cas&lt;/LI&gt;
&lt;LI&gt;/etc/pam.d/sasauth&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both files are quite standard, not really useful as default. What is more important is that it says:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;OL class="xisDoc-listSteps"&gt;
&lt;LI id="p0m1ixepks6qmqn12etey2pd01hx" class="xisDoc-step"&gt;Make any modifications to the file that are necessary for your environment.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which points to the direction What are the necessary changes and based on what?&lt;/P&gt;
&lt;P&gt;Either the documentation is missing something or I am.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see you have experience, perhaps you can help with additional details?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 16:11:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417462#M11413</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2017-11-30T16:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP / AD authentication in SAS Viya 3.2 - Full deployment</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417464#M11414</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/35204"&gt;@JuanS_OCS&lt;/a&gt;,&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Which points to the direction What are the necessary changes and based on what?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Based on you system settings. What you have in /etc/pam.d/system-auth or /etc/pam.d/system-auth-ac?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 16:11:58 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417464#M11414</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-11-30T16:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP / AD authentication in SAS Viya 3.2 - Full deployment</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417719#M11433</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;alright, that makes sense, that based on system config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let me share with you the current contents of that file:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
auth        required      pam_env.so
auth        [default=1 success=ok] pam_localuser.so
auth        [success=done ignore=ignore default=die] pam_unix.so nullok try_first_pass
auth        requisite     pam_succeed_if.so uid &amp;gt;= 1000 quiet_success
auth        sufficient    pam_sss.so forward_pass
auth        required      pam_deny.so

account     required      pam_unix.so broken_shadow
account     sufficient    pam_localuser.so
account     sufficient    pam_succeed_if.so uid &amp;lt; 1000 quiet
account     [default=bad success=ok user_unknown=ignore] pam_sss.so
account     required      pam_permit.so

password    requisite     pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=
password    sufficient    pam_unix.so sha512 shadow nullok try_first_pass use_authtok
password    sufficient    pam_sss.so use_authtok
password    required      pam_deny.so

session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
-session     optional      pam_systemd.so
session     optional      pam_oddjob_mkhomedir.so umask=0077
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     required      pam_unix.so
session     optional      pam_sss.so&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And as follow up: can anyone help me with the question 1? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 11:08:31 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417719#M11433</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2017-12-01T11:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP / AD authentication in SAS Viya 3.2 - Full deployment</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417815#M11436</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/35204"&gt;@JuanS_OCS&lt;/a&gt;,&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;And as follow up: can anyone help me with the question 1?&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This is not my area of support. I suggest you open a track, in order to contact the team which supports it.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 18:56:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/417815#M11436</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-12-01T18:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP / AD authentication in SAS Viya 3.2 - Full deployment</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/418726#M11472</link>
      <description>&lt;P&gt;Many thanks&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also shared the contents of the system PAM file. What would it be your recommendation to modify the other files?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I made a couple of tries by myself (also in sas.postgres file, on an attempt to leave SAS out of the equation and test connection to PostgreSQL), but no success.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 09:31:49 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-AD-authentication-in-SAS-Viya-3-2-Full-deployment/m-p/418726#M11472</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2017-12-06T09:31:49Z</dc:date>
    </item>
  </channel>
</rss>

