<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTLM authentication is not supported in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481455#M13717</link>
    <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/26689"&gt;@woo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you have to fix a problem with SAS/ SPN. Let me know if you need any help after that.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jul 2018 12:17:50 GMT</pubDate>
    <dc:creator>alexal</dc:creator>
    <dc:date>2018-07-26T12:17:50Z</dc:date>
    <item>
      <title>NTLM authentication is not supported</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/480982#M13693</link>
      <description>&lt;P&gt;Hello friends, we are trying to implement SSO and trying to test it with metadata server as a first step. Object spawner are SPNs registered). We have keytab file with "sas installer id" as well. Sysadmin seems completed configuration from their side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SAS 9.4 M5 Grid / Linux/ MIT kerberos/ AD/ LDAP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I generated kerberos ticket and have it on my desktop as well as on linux side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KRB5CCNAME and KRB5_CONFIG environment variables has been assigned at windows side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, when try to open sas mc with my id (userid) by selecting "use IWA (SSO)" i am receiving below error.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The application could not log on to the server. IWA failed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access denied. NTLM authentication is not supported.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;metadata log showing "NTLM authentication is not supported" as well...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any direction??? Thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 01:36:20 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/480982#M13693</guid>
      <dc:creator>woo</dc:creator>
      <dc:date>2018-07-25T01:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication is not supported</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481037#M13698</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/26689"&gt;@woo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;maybe I am wrong, but I think NTLM is not native to Linux, but Windows (servers), this means that you would need to configure in SAS pure Kerberos connectivity, removing the NTLM bits from the string.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 07:32:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481037#M13698</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2018-07-25T07:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication is not supported</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481094#M13703</link>
      <description>&lt;P&gt;Thanks Juan.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P align="LEFT"&gt;Infect SAS documents says that "When you use IWA on UNIX, only Kerberos connections are supported (there is no support for NTLM on UNIX)", and as you mentioned my errors&amp;nbsp;telling SAS still picking NTLM but I am not sure what needs to be done to tell SAS DO NOT USE NTLM,&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 12:27:14 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481094#M13703</guid>
      <dc:creator>woo</dc:creator>
      <dc:date>2018-07-25T12:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication is not supported</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481137#M13704</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/26689"&gt;@woo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;basically you need to remove the "NTLM" strings from the metadata definitions, leaving only "Kerberos".&lt;/P&gt;
&lt;P&gt;And you need to ensure the Kerberos TGTs with the keytab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The best is to refer to&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/37179"&gt;@StuartRogers&lt;/a&gt;&amp;nbsp;'s papers. He is the MAN for those topics.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/resources/papers/proceedings13/476-2013.pdf" target="_blank"&gt;http://support.sas.com/resources/papers/proceedings13/476-2013.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.sas.com/resources/papers/proceedings16/SAS3443-2016.pdf" target="_blank"&gt;https://support.sas.com/resources/papers/proceedings16/SAS3443-2016.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additionally, in SAS doc:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#n1d1zo1jsf2o0en1ehu4c4simfky.htm" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/63082/HTML/default/viewer.htm#n1d1zo1jsf2o0en1ehu4c4simfky.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.sas.com/documentation/cdl/en/bisecag/61133/HTML/default/viewer.htm#a003276221.htm#a003147113" target="_blank"&gt;http://support.sas.com/documentation/cdl/en/bisecag/61133/HTML/default/viewer.htm#a003276221.htm#a003147113&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 14:17:17 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481137#M13704</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2018-07-25T14:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication is not supported</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481216#M13708</link>
      <description>&lt;P&gt;Also, if I remove NTLM string and keep below settings in place,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;security package: Negotiate&lt;/P&gt;
&lt;P&gt;Security package list: Kerberos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it throws below error,&lt;/P&gt;
&lt;P&gt;SEC_E_TARGET_UNKNOWN&lt;/P&gt;
&lt;P&gt;security package failed while authenticating a user&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 18:22:26 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481216#M13708</guid>
      <dc:creator>woo</dc:creator>
      <dc:date>2018-07-25T18:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication is not supported</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481224#M13709</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/26689"&gt;@woo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are getting the message about NTML authentication because GSSAPI authentication has failed and it fall back to NTLM, which is next in the list. SAS does not support NTLM authentication. SEC_E_TARGET_UNKNOWN is a GSSAPI error meaning that client cannot be found in the Kerberos database. Are you sure you have created SAS/ SPN?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 18:42:00 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481224#M13709</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2018-07-25T18:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication is not supported</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481234#M13710</link>
      <description>&lt;P&gt;Thanks Alex, our sys admin team trying to figure out if they have set that correctly. For me it doesn't look like as i am not getting any output for below "setspn" cmd&amp;nbsp;from my local machine. At same time i can ping metadata server fine from local machine (windows) + nslookup resolving to metadata hostname with that ip.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;setspn -Q SAS/xyz@abc.com&lt;/P&gt;
&lt;P&gt;No such SPN found&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 19:09:53 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481234#M13710</guid>
      <dc:creator>woo</dc:creator>
      <dc:date>2018-07-25T19:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication is not supported</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481455#M13717</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/26689"&gt;@woo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, you have to fix a problem with SAS/ SPN. Let me know if you need any help after that.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 12:17:50 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/481455#M13717</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2018-07-26T12:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication is not supported</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/702886#M20846</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/26689"&gt;@woo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How did you fix this error? I am getting the same error when logging in to SAS MC with IWA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 20:11:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/NTLM-authentication-is-not-supported/m-p/702886#M20846</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2020-12-01T20:11:02Z</dc:date>
    </item>
  </channel>
</rss>

