<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/550711#M16077</link>
    <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/270459"&gt;@EmmanuelF&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you sure that a command shown below returns something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE class=" language-sas"&gt;getent passwd&amp;nbsp;ALBERT&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 12 Apr 2019 16:20:12 GMT</pubDate>
    <dc:creator>alexal</dc:creator>
    <dc:date>2019-04-12T16:20:12Z</dc:date>
    <item>
      <title>SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/550706#M16076</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I face an issue&amp;nbsp;trying to&amp;nbsp;set IWA auth for users. IWA is&amp;nbsp;functional for&amp;nbsp;web application, but i'am unable to start workspace&amp;nbsp;via SASStudio application or via EG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My configuration&amp;nbsp;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Middle tier, meta, compute on three&amp;nbsp;separate Linux server (RH)&lt;/P&gt;&lt;P&gt;-Workspace server is bind to an LDAP directory via PAM.&lt;/P&gt;&lt;P&gt;-Kerberos&amp;nbsp;binding to AD&amp;nbsp;is functionnal&amp;nbsp;&amp;nbsp;(other middle tier app starts well with IWA)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you see below, the kerberos auth and delegation seems ok, but the workspace don't start.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess that I face a user mismatch between the AD and the Ldap (users are lowercase in the ldap&amp;nbsp; eg :"albert")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wonder if there is a way to bind the username returned by the iwa auth with the ldap user as this one is used to launch the workspace.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or maybe I'am going the wrong way ???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the ObjectSpawer logs (user have been changed)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;metaserver&amp;lt; (Standard options)&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;bifrmetadev.compagny.fr&amp;lt;&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;metaport&amp;lt; (Standard options)&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;8561&amp;lt;&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;metarepository&amp;lt; (Standard options)&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT&amp;nbsp;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;Foundation&amp;lt;&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;locale&amp;lt; (Client requirement)&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;fr_FR&amp;lt;&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;objectserver&amp;lt; (Standard options)&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;objectserverparms&amp;lt; (Standard options)&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;protocol=bridge spawned spp=43996 cid=0 dnsmatch=bifrcompdev.agf.fr pb classfactory=440196D4-90F0-11D0-9F41-00A024BB830C server=OMSOBJ:SERVERCOMPONENT/A5MARO40.AY000009 cel=credentials recon&amp;lt;&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp; Environment variables are:&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;METAUSER&amp;lt;&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;ALBERT @!*(generatedpassworddomain)*!&amp;lt;&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;METAPASS&amp;lt;&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;********&amp;lt;&lt;BR /&gt;2019-04-12T14:27:54,760 DEBUG [00000057] :ALBERT - Obtained krb5 ccache handle: 7fb898021630&lt;BR /&gt;2019-04-12T14:27:54,812 DEBUG [00000057] :ALBERT - Freed krb5 ccache handle: 7fb898021630&lt;BR /&gt;2019-04-12T14:27:54,813 ERROR [00000057] :ALBERT - &lt;STRONG&gt;Access denied&lt;/STRONG&gt;.&lt;BR /&gt;2019-04-12T14:27:54,813 ERROR [00000057] :ALBERT - &lt;STRONG&gt;The launch of server SASApp - Workspace Server for user ALBERT failed.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the sasauth-debug.logcat&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;20190412-14:40:25 Authenticating user ALBERT via GSS&lt;BR /&gt;20190412-14:40:25 Context username: ALBERT @GROUPE.COMPAGNY.FR&lt;BR /&gt;20190412-14:40:25 Context username length: 24&lt;BR /&gt;20190412-14:40:25 Server Name: SAS/bifrcompdev.compagny.fr@GROUPE.COMPAGNY.FR&lt;BR /&gt;20190412-14:40:25 Unknown user when getting user attributes.&lt;BR /&gt;20190412-14:40:25 User ALBERT did not authenticate. Reason: 'Unspecified reason.' (gss)&lt;BR /&gt;20190412-14:40:25 Request failed: &lt;STRONG&gt;'User did not authenticate&lt;/STRONG&gt;.'&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 15:59:49 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/550706#M16076</guid>
      <dc:creator>EmmanuelF</dc:creator>
      <dc:date>2019-04-12T15:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/550711#M16077</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/270459"&gt;@EmmanuelF&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you sure that a command shown below returns something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE class=" language-sas"&gt;getent passwd&amp;nbsp;ALBERT&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 12 Apr 2019 16:20:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/550711#M16077</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2019-04-12T16:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/550768#M16078</link>
      <description>&lt;P&gt;Hello alexal,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;getent passwd ALBERT return nothing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;getent passwd albert return :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;albert:*:24242:20000:albert:/net/home/albert:/usr/bin/ksh&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 19:47:21 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/550768#M16078</guid>
      <dc:creator>EmmanuelF</dc:creator>
      <dc:date>2019-04-12T19:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/550818#M16080</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/270459"&gt;@EmmanuelF&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are you using for the authentication on the system level? SSSD or something else?&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2019 01:30:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/550818#M16080</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2019-04-13T01:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/551094#M16083</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes SSSD in use.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 15:36:16 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/551094#M16083</guid>
      <dc:creator>EmmanuelF</dc:creator>
      <dc:date>2019-04-15T15:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/551131#M16084</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/270459"&gt;@EmmanuelF&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to configure case insensitive usernames in SSSD. Look for case_sensitive in sssd.conf or talk to your Linux Administrator. Commands like "getent passwd ALBERT" or "getent passwd albert" have to return the same output.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 16:29:10 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/551131#M16084</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2019-04-15T16:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/551615#M16099</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;Great ! That solved the issue.&lt;/P&gt;&lt;P&gt;Thank you very much for your help&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2019 07:52:35 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/551615#M16099</guid>
      <dc:creator>EmmanuelF</dc:creator>
      <dc:date>2019-04-17T07:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: SAS 9.4 M5 - IWA - unable to start workspace for users authenticated via IWA</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/551664#M16105</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/270459"&gt;@EmmanuelF&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are welcome. I'm glad that the problem has been resolved.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2019 12:08:17 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/SAS-9-4-M5-IWA-unable-to-start-workspace-for-users-authenticated/m-p/551664#M16105</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2019-04-17T12:08:17Z</dc:date>
    </item>
  </channel>
</rss>

