<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrated windows authentication failed in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496687#M14349</link>
    <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/185092"&gt;@RupaJ&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I responded to you in the technical support track, it appears you do not have any GSSAPI libraries installed on the system. What are you using for authentication? SSSD or something else? If SSSD, then you have to install sssd-krb5-common. If something else, then you have to adjust LD_LIBRARY_PATH. &lt;/P&gt;</description>
    <pubDate>Tue, 18 Sep 2018 18:48:16 GMT</pubDate>
    <dc:creator>alexal</dc:creator>
    <dc:date>2018-09-18T18:48:16Z</dc:date>
    <item>
      <title>Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/495764#M14316</link>
      <description>&lt;P&gt;Hello Forum,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to set up IWA for the desktop clients(windows). Now my metadata /midtier and compute are on RHEL 7 servers. Meta and Midtier are on one machine, with compute on another server. SAS 9.4M5 is installed btw.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I have completed the prerequisites for setting up IWA which are&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unix host joining the AD&lt;/P&gt;&lt;P&gt;Creating the service account , UPN,SPN&lt;/P&gt;&lt;P&gt;Generating the keytab file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding the KRB5_KTNAME env variable and restart the services.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After completing all the above, I tried testing if the IWA is working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checked the Integrated windows authentication checkbox. In the advanced setting security package is "Negiciate:, SPN is the custom SPN that we have and Security Package list is "Kerberos,NTLN".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same thing mentinoed above for the workspace server properties too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I am able to connect to the SAS Enterprise guide with the profile , however my workspace server validation is failing with below error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[9/14/18 11:35 AM] INFO: Starting extended validation for Workspace server (level 1) - Making a connection&lt;BR /&gt;[9/14/18 11:35 AM] SEVERE: Access denied.&lt;BR /&gt;[9/14/18 11:35 AM] SEVERE: The launch of server SASApp - Workspace Server for user failed.&lt;BR /&gt;[9/14/18 11:35 AM] SEVERE: The application could not log on to the server "sastest.local:8591". Integrated Windows authentication failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what I see in the objectspawner logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2018-09-14T11:35:10,227 WARN [00024804] : user- The destination buffer size was not sufficient for the requested password.&lt;BR /&gt;2018-09-14T11:35:10,228 ERROR [00024804] :user - Access denied.&lt;BR /&gt;2018-09-14T11:35:10,228 ERROR [00024804] :user - The launch of server SASApp - Workspace Server for user failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note - I have removed user and server names.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now regarding the SPN, I have a question. How do I create a default SPN? My IT guy has created xyz as service account and created XYZ/sasmeta.local , XYZ/sastest.local , XYZ/sasmeta and XYZ/sastest as SPNs (both FQDN and shortnames). However I need to give SPN as "XYZ/sasmeta.local in order to connect to SASEG. It is not connecting if I leave the SPN blank when I connect to SASEG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So 2 questions&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why I am getting that error when I am trying to validate the workspace server?&lt;/P&gt;&lt;P&gt;Default SPN -- How to create?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 16:58:47 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/495764#M14316</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-14T16:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/495769#M14317</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/185092"&gt;@RupaJ&lt;/a&gt;,&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;How do I create a default SPN?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;A href="https://go.documentation.sas.com/?docsetId=bisecag&amp;amp;docsetTarget=n1d1zo1jsf2o0en1ehu4c4simfky.htm&amp;amp;docsetVersion=9.4&amp;amp;locale=en#p046wlknelasnyn1xjkevehlt9dt" target="_self"&gt;Registering SPNs&lt;/A&gt;.&amp;nbsp;The client must know the server's service principal name (SPN). In a standard configuration, this is transparent. Clients expect (and know how to construct) a default SPN in the format &lt;STRONG&gt;SAS/machine&lt;/STRONG&gt; (for example, SAS/machineA.na.company.com), so you do not have to explicitly provide the SPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Audit.Authentication logger should help with debugging GSSAPI, please add this XML to metadata/object spawner logging configuration (do not forget to restart metadata/object spawner after that):&lt;/P&gt;
&lt;PRE&gt;&lt;CODE class=" language-sas"&gt; &amp;lt;logger name="Audit.Authentication"&amp;gt;
        &amp;lt;level value="Trace"/&amp;gt;
  &amp;lt;/logger&amp;gt;&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 14 Sep 2018 17:08:56 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/495769#M14317</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2018-09-14T17:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/495801#M14318</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response. What do you mean "standard configuration"? Could you clarify. How should the default SPN be created? Any commands will be helpful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 18:38:17 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/495801#M14318</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-14T18:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/495897#M14321</link>
      <description>&lt;P&gt;Looks like I did not enable -SSPI option to launch object spawner. How do I do that? I was thinking the default is with -sspi. However after 9.4 releases, looks like default is -nosspi.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Sep 2018 11:24:18 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/495897#M14321</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-15T11:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496192#M14328</link>
      <description>&lt;P&gt;In response to the -SSPI option, I checked the object spawner startup script and it does have the -SSPI option. I guess only on windows the default is to start with -nosspi :-(. So that is ruled out too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help on this would be great. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 11:35:32 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496192#M14328</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-17T11:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496440#M14332</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&amp;nbsp;mentioned you should be able to configure the server so you don't need to specify any extra details on the client other than the basic host name, port and to use IWA. SPNs should be added in AD so the client user doesn't have to worry about them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just so you know I get that warning message in my Linux + IWA lab environment when IWA connection is successful:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;2018-09-18T10:48:43,814 INFO  [00689123] :paul - New client connection (57834) accepted from server port 8591 for IWA user paul. Encryption level is Credentials using encryption algorithm AES.  Peer IP address and port are [192.168.2.101]:52435 for APPNAME=SAS Enterprise Guide.
2018-09-18T10:48:43,859 WARN  [00689123] :paul - The destination buffer size was not sufficient for the requested password.
2018-09-18T10:48:43,884 INFO  [00689123] :paul - Created process 14210 using credentials paul (child id 94).
2018-09-18T10:48:44,490 INFO  [00689130] :sas - New out call client connection (57848) for launched server (child 94).  Peer IP address and port are [192.168.2.27]:54050.
2018-09-18T10:48:44,497 INFO  [00689130] :sas - Client connection 57834 for user paul closed.
2018-09-18T10:49:41,026 INFO  [00000009] :sas - Client connection 57848 for user paul closed.
2018-09-18T10:49:41,152 INFO  [00689122] :sas - Process 14210 owned by user paul (child id 94) has ended.&lt;/PRE&gt;
&lt;P&gt;I don't know why I am getting that buffer size warning but it does not seem to have any obvious impact. If anyone else knows how to get rid of it I'd be keen to hear. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I think you need to focus on that "Access denied" error. Have you added the&amp;nbsp;Audit.Authentication trace level logging for the object spawner as&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&amp;nbsp;suggested?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 01:21:05 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496440#M14332</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2018-09-18T01:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496521#M14337</link>
      <description>&lt;P&gt;Also, enable &lt;A href="http://support.sas.com/kb/39/891.html" target="_self"&gt;sasauth-debug&lt;/A&gt; on compute tier.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 11:25:46 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496521#M14337</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2018-09-18T11:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496524#M14338</link>
      <description>&lt;P&gt;Yes,I did enable the below in the object spawner and restarted services. However don't see any new log messages apart from what I saw before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE class=" language-sas"&gt;&lt;CODE class="  language-sas"&gt;&lt;SPAN class="token operator"&gt;&amp;lt;&lt;/SPAN&gt;logger name&lt;SPAN class="token operator"&gt;=&lt;/SPAN&gt;&lt;SPAN class="token string"&gt;"Audit.Authentication"&lt;/SPAN&gt;&lt;SPAN class="token operator"&gt;&amp;gt;&lt;/SPAN&gt;
        &lt;SPAN class="token operator"&gt;&amp;lt;&lt;/SPAN&gt;level &lt;SPAN class="token keyword"&gt;value&lt;/SPAN&gt;&lt;SPAN class="token operator"&gt;=&lt;/SPAN&gt;&lt;SPAN class="token string"&gt;"Trace"&lt;/SPAN&gt;&lt;SPAN class="token operator"&gt;/&lt;/SPAN&gt;&lt;SPAN class="token operator"&gt;&amp;gt;&lt;/SPAN&gt;
  &lt;SPAN class="token operator"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="token operator"&gt;/&lt;/SPAN&gt;logger&lt;SPAN class="token operator"&gt;&amp;gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 11:59:29 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496524#M14338</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-18T11:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496525#M14339</link>
      <description>&lt;P&gt;Where did you add these lines?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 12:01:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496525#M14339</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2018-09-18T12:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496528#M14340</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&amp;nbsp;- Yes, PROC PERMTEST went successful for my login.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 12:02:04 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496528#M14340</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-18T12:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496529#M14341</link>
      <description>&lt;P&gt;In&amp;nbsp;logconfig.xml file &amp;nbsp;in the path&amp;nbsp;/opt/sas/config/Lev1/ObjectSpawner.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 12:08:22 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496529#M14341</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-18T12:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496531#M14342</link>
      <description>&lt;P&gt;That is correct file unless object spawner is using another in logconfigloc. You do not need to run PROC PERMTEST, just enable sasauth-debug and restart the spawner. What you will see in the sasauth-debug log when the IWA/GSSAPI authentication fails?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 12:12:05 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496531#M14342</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2018-09-18T12:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496626#M14344</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like the GSS libraries are missing. What libraries shoudl I install?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Initializing gss&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Attempting to load GSSAPI library: libvas-gssapi.so&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Attempting to load GSSAPI library: /opt/quest/lib64/libvas-gssapi.so&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Attempting to load GSSAPI library: libgssapi_krb5.so&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Attempting to load GSSAPI library: libgssapi.so&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Attempting to load GSSAPI library: libgss.so&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Could not load a GSSAPI library.&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Could not initialize authentication method gss&lt;/P&gt;&lt;P&gt;20180918-08:12:41 GSS could not be loaded.&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Using maxtries: 5&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Using maxtries period: 60&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Using maxtries wait: 300&lt;/P&gt;&lt;P&gt;20180918-08:12:41 GSS is not available to process authenticate request.&lt;/P&gt;&lt;P&gt;20180918-08:12:41 Request failed: 'GSS is not available.'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 16:07:57 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496626#M14344</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-18T16:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496687#M14349</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/185092"&gt;@RupaJ&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I responded to you in the technical support track, it appears you do not have any GSSAPI libraries installed on the system. What are you using for authentication? SSSD or something else? If SSSD, then you have to install sssd-krb5-common. If something else, then you have to adjust LD_LIBRARY_PATH. &lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 18:48:16 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496687#M14349</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2018-09-18T18:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496797#M14353</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&amp;nbsp;suggested, installing&amp;nbsp;&lt;SPAN&gt;sssd-krb5-common will pull in&amp;nbsp;additional packages&amp;nbsp;including the standard open source GSSAPI libraries. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In terms of specific packages&lt;/SPAN&gt;&lt;SPAN&gt;, in my environment&amp;nbsp;/usr/lib64/libgssapi_krb5.so is a symlink (provided by the package krb5-devel) to&amp;nbsp;libgssapi_krb5.so.2.2 (provided by the package krb5-libs). The krb5-libs package is one of the dependencies&amp;nbsp;of&amp;nbsp;sssd-krb5-common.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A while ago I was having trouble with a missing /usr/lib64/libgssapi_krb5.so -&amp;gt; libgssapi_krb5.so.2.2 symlink so created it manually. Later on I found that the krb5-devel package provides it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I only use realmd to provide the&amp;nbsp;basic setup for IWA on Linux now as I find it makes it significantly easier:&amp;nbsp;&lt;A href="https://platformadmin.com/blogs/paul/2015/07/active-directory-authentication-for-sas-on-linux-with-realmd/" target="_blank"&gt;https://platformadmin.com/blogs/paul/2015/07/active-directory-authentication-for-sas-on-linux-with-realmd/&lt;/A&gt; (I just updated the blog post to add a note about&amp;nbsp;krb5-devel)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 00:02:16 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496797#M14353</guid>
      <dc:creator>PaulHomes</dc:creator>
      <dc:date>2018-09-19T00:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496876#M14355</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/18432"&gt;@PaulHomes&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have centrify that authenticates the users. Would&amp;nbsp;&lt;SPAN&gt;sssd-krb5-common package still be the one that will make it work?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 09:55:37 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496876#M14355</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-19T09:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496919#M14358</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/185092"&gt;@RupaJ&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are using Centrify, you can resolve the problem just by adding /usr/share/centrifydc/kerberos/lib64/ to the LD_LIBRARY_PATH. Also, if you do not want to change LD_LIBRARY_PATH, you can create symlinks for these files in /lib64/.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/usr/share/centrifydc/kerberos/lib64/libgssapi_krb5.so &lt;BR /&gt;/usr/share/centrifydc/kerberos/lib64/libgssapi_krb5.so.2 &lt;BR /&gt;/usr/share/centrifydc/kerberos/lib64/libgssapi_krb5.so.2.2&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 12:08:57 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/496919#M14358</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2018-09-19T12:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/497088#M14366</link>
      <description>&lt;P&gt;I just want to say that the problem has been resolved. We have linked SAS to specific GSSAPI modules, changed a few settings in sasauth.conf, and the workspace server.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 18:56:31 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/497088#M14366</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2018-09-19T18:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Integrated windows authentication failed</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/498572#M14413</link>
      <description>&lt;P&gt;Thanks so much&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&amp;nbsp;for your time!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to elaborate on what was done. I was waiting to understand few things. So the delay.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;Create the symlinks for the GSSAPI libraries on the compute server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ln -s /lib64/libgssapi_krb5.so.2.2 /lib64/libgssapi_krb5.so&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) &amp;nbsp;Add the enviornment variable in the file level_env_usermods.sh in the path /opt/sas/config/Lev1/ on the compute server&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; export TKSECURE_GSSAPI_LIBRARY=/lib64/libgssapi_krb5.so.2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) &amp;nbsp;Add the below in the file /opt/sas/sashome/SASFoundation/9.4/utilities/bin/sasauth.conf on the compute server.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;gssLibrary=/lib64/libgssapi_krb5.so.2.2&lt;/P&gt;&lt;P&gt;4) Add the below script to&amp;nbsp;/opt/sas/config/Lev1/SASApp/WorkspaceServer_usermods.sh&lt;/P&gt;&lt;PRE&gt;workspace_user=$(whoami)
workspace_user_ccaches=$(find /tmp -maxdepth 1 -user ${workspace_user} -type f -name "krb5cc_*" -printf '%T@ %p\n' | sort -k 1nr | sed 's/^[^ ]* //' | head -n 1)
 
if test ! -z "$workspace_user_ccaches"; then
            echo "Most recent krb5 ccache found for '${workspace_user}' at '${workspace_user_ccaches}'."
            echo "Cache last modified: $(stat -c%y ${workspace_user_ccaches})"
            export KRB5CCNAME=$workspace_user_ccaches
            echo "KRB5CCNAME has been set to ${KRB5CCNAME}."
else
            echo "No krb5 credentials caches were found in /tmp for '${workspace_user}'."
fi &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wish SAS documentation is modified to add these steps. It will save so much time. I hope this is useful for someone trying to configure SSO with centrify,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 20:18:55 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Integrated-windows-authentication-failed/m-p/498572#M14413</guid>
      <dc:creator>RupaJ</dc:creator>
      <dc:date>2018-09-24T20:18:55Z</dc:date>
    </item>
  </channel>
</rss>

